This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Friday, May 22, 2009

How Profits Motivates Virus Creators

The motivation behind hackers has evolved noticeably over the last couple of years. Developing harmful viruses is less about “bragging rights” or satisfying the creator’s ego and is becoming more and more about generating profit or commercial return.

The destruction of data on your computer or corruption of programs you use is a common side effect and what people have traditionally associated with a computer virus. The reformatting of your computer “c: drive”, especially at work, and the loss of valuable data used to be an incredibly painful experience.

The widespread deployment of data back up solutions within companies to comply with legislation and other factors means less and less valuable data is now stored on your computer’s local hard drive. More importantly for the virus writer this attack does not generate much tangible profit so there is not much motivation to develop more sophisticated programs to counter improved anti virus applications and corporate network security.

However, there is profit for the virus writer in turning your computer into a spam distribution machine. “Spam” is email sent without the permission of the person receiving the message. Hackers gain control of your computer through a Trojan Horse which gives them the same access rights as the user. Once your computer is controlled by the hacker it becomes known as a “Zombie.” A group of zombie machines is known as a “botnet.”

By controlling a botnet a hacker can generate profit in a number of ways. The botnet can be used to exhort a ransom from a company by threatening launch a damaging “Distributed Denial of Service” (DDoS) attack against its web site. The botnet can also be hired out to other hackers.

The most common way of profiting from a botnet is to use it to send out spam email. According to the security software company Sophos over 50% of all spam email now originates from botnets. Hackers use spam email to drive traffic to pay per click advertising sites or distribute virus programs further. Using a zombie computer helps cover their tracks.

The drive for generating profit is clearly evident in a new form of virus dubbed “Ransomware” by security experts which started to appear in 2005. Ransomware, as the name suggests, holds data on your computer “hostage.” Files on your hard drive are encrypted with a password. The user is then contacted and asked to pay a ransom to release the file.

Here are some simple tips and strategies to help prevent your computer turning into a “Zombie.”

• Keep your computer up to date with the latest software patches for Windows and other Microsoft programs. Most viruses and other malware exploit vulnerabilities in widely used programs.
• Install a reputable anti virus program. Keep the definitions up to date and scan your computer regularly.
• Install a personal firewall or buy a router with a hardware firewall. Ideally you need a firewall solution which filters both incoming and outgoing traffic from your computer to the internet.
• Never open spam email or associated email attachments which is frequently used to distribute virus programs. Use a spam filter to help reduce the amount of spam you receive.

Thursday, April 9, 2009

Safe and Secure Online Payments with SSL Certificates

The seamless world of the Internet has broken open the physical barriers that existed across regions on the Globe. Today, therefore, you could be sitting in Munich and buying goodies from Seoul. Very convenient, and thrilling. But, when you pay for your goodies and swipe you’re Credit Card, are you sure, you are paying only for what you paid for? Chances are your Credit Card Information traverses through alien territory into the wrong pair of hands. The result, the next morning, you will find your Bank account eroded or emptied? Not a situation that most of us can afford or enjoy.

How do we then transact on the Internet and yet safeguard our hard earned monies from those Electronic pirates? The answer is relatively simple. Every time you choose to buy product or services through web-sites, before entering your Credit Card and other personal information look for information on whether the payment gateway is secured. Informed customers would always prefer to transact their business through secure sites and this will automatically bring in more business to Websites secured through SSL certificates from well known providers.


Payment gateways are secured through SSL or Secured Socket Layer. When you enter your personal and or Credit Card information into a secure site, an encrypted public key is created. This is termed as a handshake to authenticate safe transaction. The unique encryption method which gets established in the process will have a unique session key. This process protects theft of valuable data and only the transaction that you intend to complete is processed.

SSL certification has been found to be very reliable across, Internet users and also among the customers. These certificates are issued by a reliable and trusted authority, the Certificate Authority. The web-site through which you are attempting to transact business carries signs of the agency which has issued the SSL certificates. There are other similar agencies too, which offer these SSL certifications. When you click on the sign, the details of the certifying agency are displayed.

When you click on such secured domains, your system generates a SSL handshake which is accessed by the web-site server. The unique encryption method employed then allows a secure transaction to go through.

Why all this bother?

When you are transacting valuable business or even sending across precious data, it is necessary to route them through secure servers which have the seal of security such as an SSL certificate. In the absence of this Security, it would compare with sending a snail mail in a transparent envelope.

For E-Commerce and other Web-site owners, the SSL certification acts as a stamp of credibility and assurance of safety to their valuable customers.

For the Service Providers and other Vendors/Merchants in the Internet world, exhibiting their site security sign – a reputed one at that, not only assures the customer that the information he parts with will be securely handled, but also separates them from the crowd. Informed customers would always prefer to transact their business through secure sites and this will automatically bring in more business to Websites secured through SSL certificates from well known providers.

Monday, March 30, 2009

Protecting your self against online credit card fraud

Today more and more people are looking to the internet to do their shopping. With online stores popping up all over the internet the urge to spend money on the World Wide Web has never been stronger. The unfortunate thing is that the urge for scam artists to take your money has never been stronger. So how do you protect your self from these thieves? If you follow these simple steps I promise you’ll enjoy shopping on the internet more having taken these precautions.

The first thing you should consider when buying online is if the website you are shopping on is secure? These days most retail websites have secure pages where you enter your personal information but that doesn’t mean that all sites are secure. The first step in making sure that your information is secure is to check the address bar and look for “https” this means that you are on a secure page. If the address begins with “http” the page is not secure and your information should not be given. The second step in determining if the website is safe is to look for the picture of a closed lock or an unbroken key. These pictures can be found in the bottom right corner of your browser window. When the lock is open or the key is broken the page is not secure. The last thing to look for is mention of secure certificates or “SSL”. These logos usually appear near the bottom of the screen. If you are still not sure if the website is secure you can always ask them through e-mail (make sure to save the reply just in case).

Credit card fraud is still relatively common. Even with all the security that some of the larger websites have, these con artists are still able to scam some people. So what do you do if you suspect that you have been scammed? The first thing you should do is determine if the charges on your credit card are really unauthorized. This is why you should save all of your receipts. Sometimes when a company makes a charge to your card it might show up on your statement as a charge from a name that you don’t recognize so it is important to check your receipts and confirmation e-mails (the company will usually tell you what the purchase will be charged as in the confirmation) to make sure that the mystery charges aren’t legitimate. Once you are sure that you have been scammed either by the store or by someone that has somehow stolen your credit card information your next step is to contact the credit card company. Some companies such as VISA and MasterCard offer zero liability for fraudulent charges. If your credit card issuer does not have a zero liability policy then you are only liable for up to $50 according to federal law.

Shopping on the internet is more popular than ever and with the flood of internet shoppers comes a wave of con artists. Protect your self from these crooks. Follow the information I have laid out for you and remember to save your receipts, look for secure pages and if that isn’t enough then only buy from well established websites that you have had good experiences with.

Sunday, March 15, 2009

Network Security – The Real Vulnerabilities

Scenario: You work in a corporate environment in which you are, at least partially, responsible for network security. You have implemented a firewall, virus and spyware protection, and your computers are all up to date with patches and security fixes. You sit there and think about the lovely job you have done to make sure that you will not be hacked.

You have done, what most people think, are the major steps towards a secure network. This is partially correct. What about the other factors?

Have you thought about a social engineering attack? What about the users who use your network on a daily basis? Are you prepared in dealing with attacks by these people?

Believe it or not, the weakest link in your security plan is the people who use your network. For the most part, users are uneducated on the procedures to identify and neutralize a social engineering attack. What’s going to stop a user from finding a CD or DVD in the lunch room and taking it to their workstation and opening the files? This disk could contain a spreadsheet or word processor document that has a malicious macro embedded in it. The next thing you know, your network is compromised.

This problem exists particularly in an environment where a help desk staff reset passwords over the phone. There is nothing to stop a person intent on breaking into your network from calling the help desk, pretending to be an employee, and asking to have a password reset. Most organizations use a system to generate usernames, so it is not very difficult to figure them out.

Your organization should have strict policies in place to verify the identity of a user before a password reset can be done. One simple thing to do is to have the user go to the help desk in person. The other method, which works well if your offices are geographically far away, is to designate one contact in the office who can phone for a password reset. This way everyone who works on the help desk can recognize the voice of this person and know that he or she is who they say they are.

Why would an attacker go to your office or make a phone call to the help desk? Simple, it is usually the path of least resistance. There is no need to spend hours trying to break into an electronic system when the physical system is easier to exploit. The next time you see someone walk through the door behind you, and do not recognize them, stop and ask who they are and what they are there for. If you do this, and it happens to be someone who is not supposed to be there, most of the time he will get out as fast as possible. If the person is supposed to be there then he will most likely be able to produce the name of the person he is there to see.

I know you are saying that I am crazy, right? Well think of Kevin Mitnick. He is one of the most decorated hackers of all time. The US government thought he could whistle tones into a telephone and launch a nuclear attack. Most of his hacking was done through social engineering. Whether he did it through physical visits to offices or by making a phone call, he accomplished some of the greatest hacks to date. If you want to know more about him Google his name or read the two books he has written.

It’s beyond me why people try and dismiss these types of attacks. I guess some network engineers are just too proud of their network to admit that they could be breached so easily. Or is it the fact that people don’t feel they should be responsible for educating their employees? Most organizations don’t give their IT departments the jurisdiction to promote physical security. This is usually a problem for the building manager or facilities management. None the less, if you can educate your employees the slightest bit; you may be able to prevent a network breach from a physical or social engineering attack.

Saturday, March 14, 2009

Microsoft Updates for Multiple Vulnerabilities

Systems Affected

* Microsoft Windows
* Windows Server


Overview


Microsoft has released updates that address vulnerabilities in Microsoft Windows and Windows Server.

I. Description

As part of the Microsoft Security Bulletin Summary for March 2009, Microsoft released updates to address vulnerabilities that affect Microsoft Windows and Windows Server.

II. Impact

A remote, unauthenticated attacker could gain elevated privileges, poison the DNS cache, execute arbitrary code, or cause a vulnerable application to crash.

III. Solution

Microsoft has provided updates for these vulnerabilities in the Microsoft Security Bulletin Summary for March 2009. The security bulletin describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. Administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS).


IV. References

* Microsoft Security Bulletin Summary for March 2009 - <http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx>
* Microsoft Windows Server Update Services - <http://technet.microsoft.com/en-us/wsus/default.aspx>
* US-CERT Vulnerability Notes for Microsoft March 2009 updates - <http://www.kb.cert.org/vuls/byid?searchview&query=ms09-mar>

Resouce:http://www.us-cert.gov/cas/techalerts/TA09-069A.html

What Are Intrusion Detection Systems?

With computer hackers and identity thieves getting more computer literate, the security your computer needs to keep them out has to always stay at least one step in front. There is a different type of computer safety tool that detects an attack or system intrusion before it has the chance to harm your computer. It is called an IDS or Intrusion Detection System and is another form of application layer firewall. Intrusion detection systems are programmed to detect attempted malicious attacks or intrusions by computer hackers trying to get into your system by detecting inappropriate, incorrect, or anomalous activity. There does seem to be some question of how well this system works when many personal computer users are going to wireless online connections. Some will argue that with the adoption of intrusion prevention technologies has created a unique challenge for security professionals. In order to make this type of system effective, such monitoring of these devices requires extensive security expertise and time. If devices are incorrectly tuned and not regularly updated, attacks of malicious traffic and intrusions may be permitted. In order to prevent downtime, security professionals also must continually check on these devices in order to keep the system running smoothly.

There are three different types of intrusion detection systems.

A host-based Intrusion Detection Systems consists of an agent on a host that can identify intrusions by analyzing system calls, application logs, and host activities. Network Intrusion Detection System is an independent platform that identifies intrusions by examining network traffic and monitors multiple hosts. These gain access to network traffic by connecting to a hub, network switch configured for port mirroring, or network tap.

Hybrid Intrusion Detection Systems combine both approaches and the host agent data is combined with network information to form a complete view of the network.

A Signature-Based Intrusion Detection System can identify intrusions by watching for patterns of traffic or application data presumed to be malicious. These systems are able to detect only known attacks, but depending on their rule set, signature based IDS's can sometimes detect new attacks which share characteristics with old attacks.

Anomaly-Based Intrusion Detection Systems identify intrusions by notifying operators of traffic or application content presumed to be different from normal activity on the network or host. Anomaly-Based Intrusion Detection Systems typically achieve this with self-learning.

A Signature-Based Intrusion Detection System identifies intrusions by watching for patterns of traffic or application data presumed to be malicious. These type of systems are presumed to be able to detect only 'known' attacks. However, depending on their rule set, signature-based IDSs can sometimes detect new attacks which share characteristics with old attacks, e.g., accessing 'cmd.exe' via a HTTP GET request.

An Anomaly-Based Intrusion Detection System identifies intrusions by notifying operators of traffic or application content presumed to be different from 'normal' activity on the network or host. Anomaly-based IDSs typically achieve this with self-learning.

Features and Benefits The Managed Intrusion Prevention Service includes:

Configure and provision device

Create initial policy; update and tune policy on an ongoing basis

Monitor and report on health and security events 24x7

Industry leading Service Level Agreement

Report all security events on the Client Resource Portal

Flexible reporting options on Client Resource Portal

Notify customers of major security and health issues

Upgrade and patch devices

Seamless integration with VeriSign's Incident Response and Computer Forensics team

Whether used for detection or prevention, Intrusion SecureNet technology is peerless in accurately detecting attacks and proactively reporting indicators of future information loss or service interruption. Using pattern matching for performance and protocol decoding to detect intentional evasion and polymorphic or patternless attacks, as well as protocol and network anomalies before a new attack has a signature created, the SecureNet System is ideal for protecting critical networks and valuable information assets.

Friday, March 13, 2009

Intrusion Prevention - IT Risk Management

Intrusion Prevention solutions detect and eliminate content-based threats from email, viruses, worms, intrusions, etc. in real time without degrading network performance. They detect and eliminate the most damaging, content-based threats from email and Web traffic such as viruses, worms, intrusions, inappropriate Web content and more in real time - without degrading network performance.

Today's global information infrastructure faces possible huge financial losses caused by ineffective Intrusion Prevention. Among the most vulnerable technologies are Providers of VoIP, video teleconferencing and data over cellular networks. While these providers have integrated into their products, the need for new Intrusion Prevention solutions is constant. Here are some of the area in which Intrusion Prevention offers effective solutions.

Instant Messaging - Intrusion Prevention
The real-time, interactive nature of Instant Messaging makes it a valuable tool for business partners, customers and fellow employees. The breach of security opportunities created by the use of IM must be managed for given its postion as a widely accepted business communications tool.

Real Time Vulnerability - Intrusion Prevention
Real Time Vulnerability Protection Suite breaks away from the reactive method of chasing attacks after they happen to eliminating and protecting vulnerabilities on your systems. By protecting against known and unknown vulnerabilities, you can ensure data reliablity and sercurity.

Network Infrastructure - Intrusion Prevention
Intrusion Prevention protect the network infrastructure to carry on your business without disruption. Enterprise level solutions offer effectevie network intrusion prevention solutions (IPS) within the context of your company's comprehensive security policy.

Email - Intrusion Prevention
Financial Companies, manufactures, retailers, etc. use intrusion prevention to scan messages and attachments for viruses. Together with "preemptive" email security approach, effective intrusion prevention offers the best protection from spam and virus attacks.

Application Level Attacks - Intrusion Prevention
A successful denial of service attack can put a corporate website off line for hours or more. Intrusion Prevention products offer the best protection against application level attacks and secure all networked applications, users and server resources.

Large Enterprises - Intrusion Prevention
Large Enterprises with widely dispersed Carrier & Data Center Networks need specially built high-performance security gateway Intrusion Prevention with proven firewall and IPSec VPN to deliver scalable network and application level security. Intrusion prevention protects the enterprise against the seemingly insignificant worm, virus, trojan, etc. that can topple its network.

Thursday, March 12, 2009

Identity Theft – Who is ‘phishing’ for your information?

There’s a new type of internet piracy called ‘phishing’ (pronounced ‘fishing’). Internet thieves are ‘fishing’ for your personal information. They’re looking for ways to trick you into giving out your Social Security Number, credit card number and other personal information that they can use to their advantage. You could become a victim of identity theft that could take years to clear your financial history and personal reputation. But understanding how these internet thieves work, will help you to protect yourself from becoming a victim.

How do these thieves get your information?
Typically, you might receive an email from a company that you are familiar with that looks ‘real’. It has the company logo, they may call you by name, and the tone of the email is that they are looking out for your best interests. This email will warn you of some imminent danger to your account or credit card and that you need to take action immediately or you will suffer dire consequences. There will be a link (underlined writing usually in blue) for you to click on that will take you to their website. And guess what? The website they take you to will look like the real thing with the company logo and all.

Next, you will be asked to ‘verify’ your account, password, or credit card information. If you ever find yourself here, STOP! Do nothing. Do not fill in any personal information. Immediately exit from this website and delete the phony email that you received.

How to know that this is a ‘phishing’ email.
If you did not email this company asking for information about your account or for help with a problem, be suspicious. If you are still not sure because it looks so ‘real’, call the company yourself and ask. You can find these phone numbers on your monthly statement. If it is after hours and no one is there to take your call, wait until the next day when you can reach someone. Don’t fall for the ‘imminent danger’ message and feel that you have to take action immediately. ‘Phishers’ are hoping that you will take immediate action – don’t panic and let them trick you into clicking on their link.

What can you do?

Never give someone your password over the internet or phone when it is an unsolicited request. Your credit card company knows what your password and credit card number is. They don’t need to ask you for it.
Likewise, your bank knows what your account number and social security number, they won’t ask you to repeat it verbally over the phone.

Review all of your monthly statements every month as soon as they arrive. Check for charges that you never made. If your statement is ever late in arriving in the mail, call and ask why. Protect yourself from these would-be thieves. Don’t let them take your identity! Please remember to Bookmark www.wheatgrass-fountain-of-youth.info now! Thanks for visiting.

Internet Monitoring, Safety And Security



www.monitoringsoftwareonline.com




Internet monitoring is a necessary part of having internet service. Whether you allow your children to surf the web or if you have the need to monitor employees, effective programs can be used to help you to do this simply. There are many aspects that can be monitored and the results can be delivered to you privately. No one needs to know that you are using internet monitoring technologies either.

There are many options when it comes to internet monitoring. No matter what your need is in these products, you can expect to use high tech gadgets and software. But, they are simplistic to use. Many software programs that monitor internet usage will tell you such things as how long the individual was online as well as what websites they visited, who they chatted with in instant messages, as well as anything that they input into the web. Emails can be tracked as well as a number of other things.

Why should you use internet monitoring? If you are not sure your employees are using their time on the job for job related tasks, this can help you know for sure. If you are unsure of who your spouse is chatting with at night, consider the use of these monitoring solutions. Do you know if someone is stalking your child as they play games on the web? If they use instant message software, find out who they are talking to and what they are saying. Internet monitoring is really a necessary part of keeping people safe and your business under control. Effective internet monitoring software products can be purchased and installed quickly and discreetly. Be in the know.

There are also many information portals now devoted to the subject and we recommend reading about it at one of these. Try googling for “internet monitoring” and you will be surprised by the abundance of information on the subject. Alternatively you may try looking on Yahoo, MSN or even a decent directory site, all are good sources of this information.

Wednesday, March 11, 2009

Don't Get Lured Into This Phishing Scam



http://static.howstuffworks.com


One good thing about writing articles for a living is that I get to learn about new things. Since I spend most of my time in front of a computer, it seems I don't get out much and unless it's on the nightly news, I don't usually hear about computer scams. That's how I found out about Phishing Scams. I had never heard of such a thing until I was asked to write an article about it, and I'm glad that I was asked. I now know what a Phishing scam is and I'm happy to share this information with you, in case your not very computer savvy either. Now most of us know enough not to openly give out personal information online to just anybody, and common sense tells us when something looks a little shaky when we see it. However, Phishing scams are hard to see because they are made to look like things we are used to. We do a lot of things online today, banking, paying bills, shopping, stock trading, etc. We usually don't give it a second thought to give our information in doing any of these activities. That's what these Phishing scams are hoping for, that you won't give a second thought to giving them your personal information.

Phishing scams usually come as emails or pop-up messages to lure your personal information from you. “We suspect an unauthorized transaction has occurred in your account. To ensure that your account is not compromised, please click the link below and confirm your identity.” Have you received an e-mail that looks like that one? Or how about; “During our regular verification of accounts, we could not verify your information. Please click here to update and verify your information.” Both of these scams are called phishing, and it involves Internet schemers who send email or pop-up messages that lure you into giving them your personal information. Credit card numbers, bank account information, Social Security numbers, and passwords, any information or sensitive material you think is safe. According to the Federal Trade Commission (FTC), phishers claim to be from a business or organization that you deal with, including Internet service providers, online payment services and even government agencies. The messages can ask you to update or confirm your account information, or threaten you if you don't respond immediately. The messages will then direct you to a website that looks just like the one you're used to dealing with, but it's not, it's a fake website and its only purpose is to trick you into giving out your personal information.

FTC recommends never give out personal information to email or pop ups that ask you for it. Legitimate companies never ask for this information via email. Don't cut and paste a link from the message into your Internet browser. Don't “click” on a button or web address given to you via email unless you're absolutely sure of were its going. For more information, look for websites pertaining to phishing scam information.

Tuesday, March 10, 2009

Deliver Your Web Site From Evil (Part 1)

1. Backup your website on the server.

If you have more than one important web site, put them on different web hosts. Don't rely on your web host for backups.

Find two different hosts which allow SSH access. Get an account with each. FTP the backup of one site to the other server directly, and vice versa. Download copies to your home computer as well.

2. Put a file called 'index.html' in every major or important directory in your website, if it doesn't already have one.

This stops people trying to peek at other files in the same directory.

3. Do not use old versions of FormMail. Do not use scripts that are newly released, unless you know how to check for security holes.

They should filter input like \# or >. Search on the terms 'Script Name bug' or 'Script Name security'.

4. Rename any email scripts you download before installing them.

Why give a spammer a clue as to what your script is, and what it can do?

5. Do not give files or directories obvious names, like 'pass', 'emails', 'orders' and the like.

Again, why make it easy for snoopers?

6. Do not leave unencrypted, confidential information on your server.

It's only a computer in a room God knows where, with God knows who having access to it.

7. Use a popular web host.

That cheapo one might be an un-committed reseller. Their Google PageRank gives a clue as to how popular they are. Send them an email or two. See how long it takes to get a reply. Check out their forums; how busy are they? They don't have a forum? Next!

8. If you are setting up .htaccess files or any other type of password protection, use long and varied passwords.

"Ch33s3And0n10n" is a lot more secure than "cheeseandonion", and just as memorable. Make your password at least 8 characters in length, containing both letters and numbers, and both upper and lower-case letters. Ordinary words can be guessed by brute-force cracking programs.

9. Strip scripts down to the bare essentials. Upgrade them regularly.

Programs like PHPNuke have lots of features in the default install. They allow webmasters and users a lot of control of website content. This creates vulnerabilities. A 'Nuke site of mine was hacked during Christmas 2005, by an Arabian group. Fortunately, I had a backup. I didn't have fast internet access, at the time, to upgrade it. I only needed one module working, so I removed the inessential ones, and changed file permissions on the admin section. At the time of writing, I'm waiting to see what happens next!

If you don't truly need it, turn it off.

10. Be careful what you say about other people or products on your site.

Not really security, but... people are very touchy about criticism. 'Flame wars' are a waste of time and energy, so avoid them.

6 Tips To Secure Your Website



www.ecommerce-blog.org


Most people on the internet are good, honest people. However, there are some people browsing the internet who derive fun from poking around websites and finding security holes. A few simple tips can help you secure your website in the basic ways. Now, obviously, the subject of data security is a complicated one and way beyond the scope of this column. However, I will address the very basics one should do which will alleviate many potential problems that might allow people to see things they shouldn't.

Password Protecting Directories

If you have a directory on your server which should remain private, do not depend on people to not guess the name of the directory. It is better to password protect the folder at the server level. Over 50% of websites out there are powered by Apache server, so let's look at how to password protect a directory on Apache.

Apache takes configuration commands via a file called .htaccess which sits in the directory. The commands in .htaccess have effect on that folder and any sub-folder, unless a particular sub-folder has its own .htaccess file within. To password protect a folder, Apache also uses a file called .htpasswd . This file contains the names and passwords of users granted access. The password is encrypted, so you must use the htpasswd program to create the passwords. To access it, go to the command line of your server and type htpasswd. If you receive a "command not found" error then you need to contact your system admin. Also, bear in mind that many web hosts provide web-based ways to secure a directory, so they may have things set up for you to do it that way rather than on your own. Barring this, let's continue.

Type "htpasswd -c .htpasswd myusername" where "myusername" is the username you want. You will then be asked for a password. Confirm it and the file will be created. You can double check this via FTP. Also, if the file is inside your web folder, you should move it so that it is not accessible to the public. Now, open or create your .htaccess file. Inside, include the following:

AuthUserFile /home/www/passwd/.htpasswd
AuthGroupFile /dev/null
AuthName "Secure Folder"
AuthType Basic

require valid-user


On the first line, adjust the directory path to wherever your .htpasswd file is. Once this is set up, you will get a popup dialog when visiting that folder on your website. You will be required to log in to view it.

Turn Off Directory Listings

By default, any directory on your website which does not have a recognized homepage file (index.htm, index.php, default.htm, etc.) is going to instead display a listing of all the files in that folder. You might not want people to see everything you have on there. The simplest way to protect against this is to simply create a blank file, name it index.htm and then upload it to that folder. Your second option is to, again, use the .htaccess file to disable directory listing. To do so, just include the line "Options -Indexes" in the file. Now, users will get a 403 error rather than a list of files.

Remove Install Files

If you install software and scripts to your website, many times they come with installation and/or upgrade scripts. Leaving these on your server opens up a huge security problem because if somebody else is familiar with that software, they can find and run your install/upgrade scripts and thus reset your entire database, config files, etc. A well written software package will warn you to remove these items before allowing you to use the software. However, make sure this has been done. Just delete the files from your server.

Keep Up with Security Updates

Those who run software packages on their website need to keep in touch with updates and security alerts relating to that software. Not doing so can leave you wide open to hackers. In fact, many times a glaring security hole is discovered and reported and there is a lag before the creator of the software can release a patch for it. Anybody so inclined can find your site running the software and exploit the vulnerability if you do not upgrade. I myself have been burned by this a few times, having whole forums get destroyed and having to restore from backup. It happens.

Reduce Your Error Reporting Level

Speaking mainly for PHP here because that's what I work in, errors and warnings generated by PHP are, by default, printed with full information to your browser. The problem is that these errors usually contain full directory paths to the scripts in question. It gives away too much information. To alleviate this, reduce the error reporting level of PHP. You can do this in two ways. One is to adjust your php.ini file. This is the main configuration for PHP on your server. Look for the error_reporting and display_errors directives. However, if you do not have access to this file (many on shared hosting do not), you can also reduce the error reporting level using the error_reporting() function of PHP. Include this in a global file of your scripts that way it will work across the board.

Secure Your Forms

Forms open up a wide hole to your server for hackers if you do not properly code them. Since these forms are usually submitted to some script on your server, sometimes with access to your database, a form which does not provide some protection can offer a hacker direct access to all kinds of things. Keep in mind...just because you have an address field and it says "Address" in front of it does not mean you can trust people to enter their address in that field. Imagine your form is not properly coded and the script it submits to is not either. What's to stop a hacker from entering an SQL query or scripting code into that address field? With that in mind, here are a few things to do and look for:

Use MaxLength. Input fields in form can use the maxlength attribute in the HTML to limit the length of input on forms. Use this to keep people from entering WAY too much data. This will stop most people. A hacker can bypass it, so you must protect against information overrun at the script level as well.

Hide Emails If using a form-to-mail script, do not include the email address into the form itself. It defeats the point and spam spiders can still find your email address.

Use Form Validation. I won't get into a lesson on programming here, but any script which a form submits to should validate the input received. Ensure that the fields received are the fields expected. Check that the incoming data is of reasonable and expected length and of the proper format (in the case of emails, phones, zips, etc.).

Avoid SQL Injection. A full lesson on SQL injection can be reserved for another article, however the basics is that form input is allowed to be inserted directly into an SQL query without validation and, thus, giving a hacker the ability to execute SQL queries via your web form. To avoid this, always check the data type of incoming data (numbers, strings, etc.), run adequate form validation per above, and write queries in such a way that a hacker cannot insert anything into the form which would make the query do something other than you intend.

Conclusion

Website security is a rather involved subject and it get a LOT more technical than this. However, I have given you a basic primer on some of the easier things you can do on your website to alleviate the majority of threats to your website.

Monday, March 9, 2009

Internet Security: The Secure Free Option

This high speed revolution has increased the swiftness of accessibility for unscrupulous hackers to upload private information quickly and easily, through your home internet connection.

With the threat of viruses, identity fraud, phishing, spyware and keyloggers, never has it been more important to protect the valuable contents of your home computer.

There are many types of internet security software out there, which offer varying ranges of performance when it comes to security. The most popular software requires the computer owner to purchase a license and download the software over the internet or buy the software from a reputable computer outlet for a set fee which includes 12 months of free updates, with a view to paying a further fee every 12 months to keep this update service going, this for some computer owners can be a slightly expensive encounter and can put owners off placing that all important security software on their home computer.

Is there a FREE and secure alternative? The answer I’m happy to say is yes.

Home internet security comes in four main categories of protection, Spyware Protection, Anti-Virus Protection, Firewall Protection and Windows Updates.

Spyware Protection

Spybot found at www.spybot.info is an excellent free spyware removal tool which helps clear your system of any threats from Adware, Keyloggers, Malware etc, the program is very easy to use and updates can be downloaded for free and are updated on a regular basis to help make sure you are protected.

Anti-virus Protection


Avast! Anti-virus found at www.avast.com is a more than adequate anti-virus protection, registration is absolutely free for home and small business users and just requires the user to register once every twelve months, which is a very small burden especially when you can download virus definitions and program updates totally free.

Firewall Protection

Sygate Personal Firewall found at www.sygate.com is again a totally free for home and small business users personal firewall, the setup of the program is very user friendly and can easily be setup by someone with little computer knowledge. The protection is highly suitable and very secure.

Windows Update

All computer users should make it their fortnightly chore to visit the Windows update service and download the latest security patches, these are most important to cover any floors which have been discovered in Microsoft applications. You can also switch the update to automatic, so when important downloads are available windows will download them using low bandwidth, so not to disturb your internet browsing.

CONCLUSION

Internet security is a high priority for all computer users, and whether this service is paid for or users wish to take advantage of the three excellent and secure software programs above for free, that is completely up to the individual. Some sort of internet security is better than none at all.

Thursday, March 5, 2009

Protecting your personal information

Avoiding the phishers


"The vandals are becoming fraudsters and electronic pickpockets."
Identity thieves are using more sophisticated methods to get consumers to divulge their personal and confidential information.

Bill Rosenkrantz, group product manager for internet security firm Symantec, says that in the last seven years, the internet has gone from an information source to an ATM: "Thirty-five to 40 per cent in the U.S. use the internet for financial transactions."

"Historically, hackers and virus writers would attack systems for ego's sake. But now it's financial," according to Rosenkrantz. "The vandals are becoming fraudsters and electronic pickpockets."

How to avoid getting "phished" in

  • Don't respond to e-mails requesting your personal information.

  • Don't click on links inside e-mails-

  • If you're uncertain about a website address that appears in an e-mail, go to your browser and enter the legitimate address manually.

  • Protect your computer -Use updated anti-virus software,.


  • Report suspicious e-mails

  • Notify the legitimate company if you receive any e-mails that you think might be fraudulent.

    More information at http://www.cbc.ca

    Tuesday, March 3, 2009

    "Koobface" Worm Resurfaces on Facebook, MySpace

    Security experts are warning users of Facebook, MySpace and other social networking communities to be on guard against a new strain of the "Koobface" worm, which spreads by tricking users into responding to a message apparently sent from one of their friends.

    The latest version of Koobface arrives as an invitation from a user's friend or contact, inviting the recipient to click on a link and view a video at a counterfeit YouTube site. Visitors are told they need need to install an Adobe Flash plug-in to view the video.

    The bogus plug-in instead installs a Trojan horse program that gives Koobface author(s) control over the infected user's computer, according to security firm Trend Micro, which documented the new strain on its blog...

    More information

    Tigger.A: Sophisticated trojan that likes stockbrokers

    Tigger.A: Sophisticated trojan that likes stockbrokers
    Customers and employees of firms that trade stocks and options beware, the Tigger.
    A trojan is targeting you. Tigger/Syzor is one of the most sophisticated pieces of malware that exists today.
    “The trojan uses a privilege escalation vulnerability (MS08-066), which is almost an exact replica of the public exploit on Milw0rm. It disables Windows Defender, Windows Firewall, Outpost, Avira, Kaspersky, AVG, and CA products in unique ways such as posting malformed messages to windows owned by the daemon processes, sending special byte codes over named pipes, and using the products’ own API.”

    “It installs a rootkit that runs in safe mode. The rootkit disables kernel debuggers, hooks FAT and NTFS file system drivers, and also prevents other processes from accessing the kernel driver’s memory so tools like GMER and IceSword can’t recover the .sys from RAM.

    Tigger of course also injects code into user-mode processes. This component takes screen shots, hooks COM for spying on browser events, and exports passwords (protected storage, network and dial-up, and at least 11 popular chat, email, and remote access applications). It also steals web cookies, steals certificates, and puts the NIC in promiscuous mode to sniff FTP and POP3 passwords.”


    More information on http://blogs.techrepublic.com.com/security/?p=960

    Sunday, March 1, 2009

    Trojan Horse

    The original trojan horse was built by Odysseus, the King of Ithica, during the legendary Trojan Wars. The Greeks were losing the siege of the city of Troy. Odysseus had a large wooden horse built and left as a "gift" outside the walls of the city of Troy. He then ordered the Greek army to sail away.

    The Trojans believed the horse to be a peace offering from Odysseus. Instead, the horse was filled with Greek warriors, including Odysseus and Menelaus. As the Trojans slept, the Greek army sailed back to Troy and the soldiers hiding in the wooden horse snuck out and opened the gates of the city for them.

    The Computer Trojan Horse

    A computer trojan horse is a program which appears to be something good, but actually conceals something bad.

    One way to spread a trojan horse is to hide it inside a distribution of normal software. In 2002, the sendmail and OpenSSH packages were both used to hide trojan horses. This was done by an attacker who broke into the distribution sites for these software packages and replaced the original distributions with his own packages.

    A more common method of spreading a trojan horse is to send it via e-mail. The attacker will send the victim an e-mail with an attachment called something like "prettygirls.exe." When the victim opens the attachment to see the pretty girls, the trojan horse will infect his system.

    A similar technique for spreading trojan horses is to send files to unsuspecting users over chat systems like IRC, AIM, ICQ, MSN, or Yahoo Messenger.

    The Trojan Horses Virus

    Unlike viruses, trojan horses do not normally spread themselves. Trojan horses must be spread by other mechanisms.
    A trojan horse virus is a virus which spreads by fooling an unsuspecting user into executing it.

    An example of a trojan horse virus would be a virus which required a user to open an e-mail attachment in Microsoft Outlook to activate. Once activated, the trojan horse virus would send copies of itself to people in the Microsoft Outlook address book.
    The trojan horse virus infects like a trojan horse, but spreads like a virus.

    Effects of a Trojan Horse

    The victim running the trojan horse will usually give the attacker some degree of control over the victim's machine. This control may allow the attacker to remotely access the victim's machine, or to run commands with all of the victim's privileges.

    The trojan horse could make the victim's machine part of a Distributed Denial of Service (DDoS) network, where the victims machine is used to attack other victims.

    Alternatively, the trojan horse could just send data to the attacker. Data commonly targeted by trojan horses includes usernames and passwords, but a sophisticated trojan horse could also be programmed to look for items such as credit card numbers.

    Protecting Against a Trojan Horse

    Anti-virus programs detect known trojan horses. However, trojan horse programs are easier to create than viruses and many are created in small volumes. These trojan horse programs will not be detected by anti-virus software.

    The best defense against a trojan horse is to never run a program that is sent to you. E-mail and chat systems are not safe methods of software distribution.

    Spyware and adware

    Many people consider spyware and adware to be forms of a trojan horse.
    Spyware programs perform a useful function, and also install a program that monitors usage of the victim's computer for the purpose of marketing to the user.

    Adware programs are similiar to spyware programs, except the additional software they install shows advertising messages directly to the user.

    Saturday, February 28, 2009

    SQL Hack




    Paperback: 410 pages
    Publisher: O'Reilly Media, Inc. (November 21, 2006)
    Language: English
    ISBN-10: 0596527993

    Whether you're running Access, MySQL, SQL Server, Oracle, or PostgreSQL, this book will help you push the limits of traditional SQL to squeeze data effectively from your database. The book offers 100 hacks -- unique tips and tools -- that bring you the knowledge of experts who apply what they know in the real world to help you take full advantage of the expressive power of SQL. You'll find practical techniques to address complex data manipulation problems. Learn how to:

    * Wrangle data in the most efficient way possible
    * Aggregate and organize your data for meaningful and accurate reporting
    * Make the most of subqueries, joins, and unions
    * Stay on top of the performance of your queries and the server that runs them
    * Avoid common SQL security pitfalls, including the dreaded SQL injection attack

    Let SQL Hacks serve as your toolbox for digging up and manipulating data. If you love to tinker and optimize, SQL is the perfect technology and SQL Hacks is the must-have book for you.

    Free System Scan: RegistryBooster



    How many .exe related errors does your computer have?

    You no longer need to guess... this Free System Scan will give you a complete diagnosis and deep scan of your registry for Errors and Conflicts.

    Instant Scan

    The Problem

    Have you noticed that the longer you have your computer, the slower it runs and the more it crashes? Often this phenomenon is caused by problems in the registry that accrue over time. Installing and uninstalling programs leave behind fragments — stray files, orphaned startup tasks, corrupted drivers. Over time the registry starts to get bogged down and conflicts emerge. Left unchecked, your system will become increasingly unstable, run more slowly and crash more frequently.

    The Solution

    RegistryBooster is the easy answer to registry problems. It conducts deep scans of your registry to check for errors and conflicts, then repairs and optimizes the registry to peak performance and stability. Periodic scans will keep your registry "clean" and will greatly enhance your system’s performance and stability. You’ll see immediate increases in speed and decreases in system conflicts.

    2 minutes can save you months of frustration and crashes

    Instant Scan

    Key Benefits of Registry Booster 2:



    • Clean Your System and Boost Performance

    Boost system performance by cleaning out all missing, unwanted, obsolete and corrupt registry entries automatically with Registry Booster 2.
    • Repair Your PC and Keep It Tuned
    Dramatically improve your computing experience by repairing all registry problems and minimizing application seizures and crashes.
    • Exceptionally Simple to Use
    Set in a highly intuitive, attractive, logical and user-friendly graphical user interface, Uniblue’s registry cleaner sets the standard for ease-of-use.
    • More Scanning Options
    Due to the improvements made to the scanning engine you are now able to scan for more sections within the registry.
    • An Ignore List
    This is quite an innovative feature and very useful for those users who are extra cautious with their registry. By specifying the Registry section and path the user will be able to exclude registry parts from the scan.
    • Log Generation
    Displays a transcript of all the actions performed on the registry by a particular fix operation. Especially helpful for those users wanting to know what has been done to their registry.
    • Windows Vista Compatible
    RegistryBooster 2 is now fully Windows Vista Compatible and can still be run on Windows XP and 2000. The program automatically adapts itself according to the version of your operating system so you do not have to configure any manual settings.
    • Safe and Trusted
    Avoid crashes, seizures, slow downs and error messages with the safest and most trusted solution from a leading software vendor.