This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Showing posts with label internet safety. Show all posts
Showing posts with label internet safety. Show all posts

Tuesday, April 21, 2009

How to Prevent Identity Theft

Internet banking is a piece of cake for all those who know how to handle it. Free online bill-payment, the 'next day’ bank to bank funds transfer and much more, are some of its features that make your life so much easier. But, with this bliss you may also invite a serious trouble. One of the worst things that could happen to you is someone using your identity to borrow money from creditors and stealing money from your bank accounts. This is called Identity theft.

One would only need two pieces of your personal information to impersonate you: your date of birth (DOB) and your Social Security Number (SSN). Technically, these are the keys to your bank accounts, credit files, credit cards, health information and everything. No matter how fool proof banking might be these days you are ALWAYS at a risk of being a victim of Identity theft.

More Information at: www.ehow.com

Sunday, March 15, 2009

Network Security – The Real Vulnerabilities

Scenario: You work in a corporate environment in which you are, at least partially, responsible for network security. You have implemented a firewall, virus and spyware protection, and your computers are all up to date with patches and security fixes. You sit there and think about the lovely job you have done to make sure that you will not be hacked.

You have done, what most people think, are the major steps towards a secure network. This is partially correct. What about the other factors?

Have you thought about a social engineering attack? What about the users who use your network on a daily basis? Are you prepared in dealing with attacks by these people?

Believe it or not, the weakest link in your security plan is the people who use your network. For the most part, users are uneducated on the procedures to identify and neutralize a social engineering attack. What’s going to stop a user from finding a CD or DVD in the lunch room and taking it to their workstation and opening the files? This disk could contain a spreadsheet or word processor document that has a malicious macro embedded in it. The next thing you know, your network is compromised.

This problem exists particularly in an environment where a help desk staff reset passwords over the phone. There is nothing to stop a person intent on breaking into your network from calling the help desk, pretending to be an employee, and asking to have a password reset. Most organizations use a system to generate usernames, so it is not very difficult to figure them out.

Your organization should have strict policies in place to verify the identity of a user before a password reset can be done. One simple thing to do is to have the user go to the help desk in person. The other method, which works well if your offices are geographically far away, is to designate one contact in the office who can phone for a password reset. This way everyone who works on the help desk can recognize the voice of this person and know that he or she is who they say they are.

Why would an attacker go to your office or make a phone call to the help desk? Simple, it is usually the path of least resistance. There is no need to spend hours trying to break into an electronic system when the physical system is easier to exploit. The next time you see someone walk through the door behind you, and do not recognize them, stop and ask who they are and what they are there for. If you do this, and it happens to be someone who is not supposed to be there, most of the time he will get out as fast as possible. If the person is supposed to be there then he will most likely be able to produce the name of the person he is there to see.

I know you are saying that I am crazy, right? Well think of Kevin Mitnick. He is one of the most decorated hackers of all time. The US government thought he could whistle tones into a telephone and launch a nuclear attack. Most of his hacking was done through social engineering. Whether he did it through physical visits to offices or by making a phone call, he accomplished some of the greatest hacks to date. If you want to know more about him Google his name or read the two books he has written.

It’s beyond me why people try and dismiss these types of attacks. I guess some network engineers are just too proud of their network to admit that they could be breached so easily. Or is it the fact that people don’t feel they should be responsible for educating their employees? Most organizations don’t give their IT departments the jurisdiction to promote physical security. This is usually a problem for the building manager or facilities management. None the less, if you can educate your employees the slightest bit; you may be able to prevent a network breach from a physical or social engineering attack.

Thursday, March 5, 2009

Protecting your personal information

Avoiding the phishers


"The vandals are becoming fraudsters and electronic pickpockets."
Identity thieves are using more sophisticated methods to get consumers to divulge their personal and confidential information.

Bill Rosenkrantz, group product manager for internet security firm Symantec, says that in the last seven years, the internet has gone from an information source to an ATM: "Thirty-five to 40 per cent in the U.S. use the internet for financial transactions."

"Historically, hackers and virus writers would attack systems for ego's sake. But now it's financial," according to Rosenkrantz. "The vandals are becoming fraudsters and electronic pickpockets."

How to avoid getting "phished" in

  • Don't respond to e-mails requesting your personal information.

  • Don't click on links inside e-mails-

  • If you're uncertain about a website address that appears in an e-mail, go to your browser and enter the legitimate address manually.

  • Protect your computer -Use updated anti-virus software,.


  • Report suspicious e-mails

  • Notify the legitimate company if you receive any e-mails that you think might be fraudulent.

    More information at http://www.cbc.ca

    Sunday, March 1, 2009

    Trojan Horse

    The original trojan horse was built by Odysseus, the King of Ithica, during the legendary Trojan Wars. The Greeks were losing the siege of the city of Troy. Odysseus had a large wooden horse built and left as a "gift" outside the walls of the city of Troy. He then ordered the Greek army to sail away.

    The Trojans believed the horse to be a peace offering from Odysseus. Instead, the horse was filled with Greek warriors, including Odysseus and Menelaus. As the Trojans slept, the Greek army sailed back to Troy and the soldiers hiding in the wooden horse snuck out and opened the gates of the city for them.

    The Computer Trojan Horse

    A computer trojan horse is a program which appears to be something good, but actually conceals something bad.

    One way to spread a trojan horse is to hide it inside a distribution of normal software. In 2002, the sendmail and OpenSSH packages were both used to hide trojan horses. This was done by an attacker who broke into the distribution sites for these software packages and replaced the original distributions with his own packages.

    A more common method of spreading a trojan horse is to send it via e-mail. The attacker will send the victim an e-mail with an attachment called something like "prettygirls.exe." When the victim opens the attachment to see the pretty girls, the trojan horse will infect his system.

    A similar technique for spreading trojan horses is to send files to unsuspecting users over chat systems like IRC, AIM, ICQ, MSN, or Yahoo Messenger.

    The Trojan Horses Virus

    Unlike viruses, trojan horses do not normally spread themselves. Trojan horses must be spread by other mechanisms.
    A trojan horse virus is a virus which spreads by fooling an unsuspecting user into executing it.

    An example of a trojan horse virus would be a virus which required a user to open an e-mail attachment in Microsoft Outlook to activate. Once activated, the trojan horse virus would send copies of itself to people in the Microsoft Outlook address book.
    The trojan horse virus infects like a trojan horse, but spreads like a virus.

    Effects of a Trojan Horse

    The victim running the trojan horse will usually give the attacker some degree of control over the victim's machine. This control may allow the attacker to remotely access the victim's machine, or to run commands with all of the victim's privileges.

    The trojan horse could make the victim's machine part of a Distributed Denial of Service (DDoS) network, where the victims machine is used to attack other victims.

    Alternatively, the trojan horse could just send data to the attacker. Data commonly targeted by trojan horses includes usernames and passwords, but a sophisticated trojan horse could also be programmed to look for items such as credit card numbers.

    Protecting Against a Trojan Horse

    Anti-virus programs detect known trojan horses. However, trojan horse programs are easier to create than viruses and many are created in small volumes. These trojan horse programs will not be detected by anti-virus software.

    The best defense against a trojan horse is to never run a program that is sent to you. E-mail and chat systems are not safe methods of software distribution.

    Spyware and adware

    Many people consider spyware and adware to be forms of a trojan horse.
    Spyware programs perform a useful function, and also install a program that monitors usage of the victim's computer for the purpose of marketing to the user.

    Adware programs are similiar to spyware programs, except the additional software they install shows advertising messages directly to the user.