This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Monday, March 30, 2009

Identity Theft – Who is phishing for your information?

There’s a new type of internet piracy called phishing (pronounced fishing). Internet thieves are fishing for your personal information. They’re looking for ways to trick you into giving out your Social Security Number, credit card number and other personal information that they can use to their advantage. You could become a victim of identity theft that could take years to clear your financial history and personal reputation. But understanding how these internet thieves work, will help you to protect yourself from becoming a victim.

How do these thieves get your information?
Typically, you might receive an email from a company that you are familiar with that looks real. It has the company logo, they may call you by name, and the tone of the email is that they are looking out for your best interests. This email will warn you of some imminent danger to your account or credit card and that you need to take action immediately or you will suffer dire consequences. There will be a link (underlined writing usually in blue) for you to click on that will take you to their website. And guess what? The website they take you to will look like the real thing with the company logo and all.

Next, you will be asked to verify your account, password, or credit card information. If you ever find yourself here, STOP! Do nothing. Do not fill in any personal information. Immediately exit from this website and delete the phony email that you received.

How to know that this is a phishing email.
If you did not email this company asking for information about your account or for help with a problem, be suspicious. If you are still not sure because it looks so real, call the company yourself and ask. You can find these phone numbers on your monthly statement. If it is after hours and no one is there to take your call, wait until the next day when you can reach someone. Don’t fall for the imminent danger message and feel that you have to take action immediately. Phishers are hoping that you will take immediate action – don’t panic and let them trick you into clicking on their link.

What can you do?
Never give someone your password over the internet or phone when it is an unsolicited request. Your credit card company knows what your password and credit card number is. They don’t need to ask you for it.
Likewise, your bank knows what your account number and social security number, they won’t ask you to repeat it verbally over the phone.

Review all of your monthly statements every month as soon as they arrive. Check for charges that you never made. If your statement is ever late in arriving in the mail, call and ask why. Protect yourself from these would-be thieves. Don’t let them take your identity! Please remember to Bookmark Internet Security Center now! Thanks for visiting.

Brought to you by http://www.PrePaid-Legal-Help-4U.com where you have complete legal protection 24/7 for less than $1 a day!

Protecting your self against online credit card fraud

Today more and more people are looking to the internet to do their shopping. With online stores popping up all over the internet the urge to spend money on the World Wide Web has never been stronger. The unfortunate thing is that the urge for scam artists to take your money has never been stronger. So how do you protect your self from these thieves? If you follow these simple steps I promise you’ll enjoy shopping on the internet more having taken these precautions.

The first thing you should consider when buying online is if the website you are shopping on is secure? These days most retail websites have secure pages where you enter your personal information but that doesn’t mean that all sites are secure. The first step in making sure that your information is secure is to check the address bar and look for “https” this means that you are on a secure page. If the address begins with “http” the page is not secure and your information should not be given. The second step in determining if the website is safe is to look for the picture of a closed lock or an unbroken key. These pictures can be found in the bottom right corner of your browser window. When the lock is open or the key is broken the page is not secure. The last thing to look for is mention of secure certificates or “SSL”. These logos usually appear near the bottom of the screen. If you are still not sure if the website is secure you can always ask them through e-mail (make sure to save the reply just in case).

Credit card fraud is still relatively common. Even with all the security that some of the larger websites have, these con artists are still able to scam some people. So what do you do if you suspect that you have been scammed? The first thing you should do is determine if the charges on your credit card are really unauthorized. This is why you should save all of your receipts. Sometimes when a company makes a charge to your card it might show up on your statement as a charge from a name that you don’t recognize so it is important to check your receipts and confirmation e-mails (the company will usually tell you what the purchase will be charged as in the confirmation) to make sure that the mystery charges aren’t legitimate. Once you are sure that you have been scammed either by the store or by someone that has somehow stolen your credit card information your next step is to contact the credit card company. Some companies such as VISA and MasterCard offer zero liability for fraudulent charges. If your credit card issuer does not have a zero liability policy then you are only liable for up to $50 according to federal law.

Shopping on the internet is more popular than ever and with the flood of internet shoppers comes a wave of con artists. Protect your self from these crooks. Follow the information I have laid out for you and remember to save your receipts, look for secure pages and if that isn’t enough then only buy from well established websites that you have had good experiences with.

Sunday, March 29, 2009

Your Next PR Nightmare Could Be Only a Click Away

In the age of Enron and failed intelligence, scandals remain the rage of the front page. Companies want to see positive spin and not scandal related material published. Imagine for a moment the educational software site where employees are identified as regular visitors to pornography websites. The effect to such a company’s image could be devastating.

Leaks, Peeks & Sneaks

There are numerous security risks facing companies with internal networks. Primary among their concerns are stifling leaks and backdoors that allow hackers to penetrate their firewalls. But the threat from within the company may prove to be more devastating to a company’s reputation and subsequently their stock value and much more.

Employees face a four-pronged attack from blended threats across the board. Phishing and pharming are two of the more popular attacks that face Internet users everyday. Typically sent via email, phishing attacks depend on the concern of an employee to take care of matters ranging from personal to financial. The uneducated user will click an embedded link and leave the network vulnerable to an attack.

The sophistication of these attacks can penetrate even the most complex of security systems unless user error can be compensated for. The most popular forms of phishing involve instant messaging and emails. Despite the widely known understanding of spoofing, most users do not expect to receive messages from spoofed accounts.

Increasing a systems security perimeter can block instant messaging ports and prevent such external security breaches. Network security devices can also block web requests to URLs presented in instant messages. Better still, URLs or web requests from internal users can be compared to a database of acceptable websites and disallowed or denied if they do not match.

Living on the Fringe

Installing spyware and malware is another by-product of visiting less than secure websites. Internet users are often besieged by offers for free software, free access and freebies. The lure of the freebie is as potent if not more so on the Internet than it is in real life. Downloading such freebies can come with passenger programs designed to record keystrokes and much more.

The least of the problems that spyware can commit is to tie up bandwidth and computer memory. The worst is that it can actually spawn Internet attacks to other sites, download critical data and send it elsewhere. Employees do not have to be lured just by a freebie either. They can simply make a typo in submitting a URL and find themselves in the wrong Internet neighborhood. Clever programmers can generate pop-up windows and disguise a button with a simple label like ‘close’ and the user will click it, thinking they will only close the nuisance window. Some programs on high-speed network access can be downloaded in the blink of an eye, compromising the computer and potentially the network.

One-Click Scandals

Scandals need very little fuel to fire. A user who chooses to go to a website of questionable integrity and intent and a user who is lured there by a bad link or a typo offer the same type of danger to a company. Scandals do not have to make the front page to generate reputation-damaging issues for a company.

Word of mouth is as fast a delivery service for reputation sabotage as press reporting is. A network security company that cannot protect against hacking of their website does not engender trust or confidence. A financial investment firm that is accused of insider trading when emails and instant messages from employees are subpoenaed and found to be questionable will likely lose clients, capital and more.

The Burden of Responsibility

Scandal can be generated by an innocent act as easily as by one of guilty intent. Corporations are responsible for the actions of their employees. Questionable Internet behavior and activity can and will affect a company’s reputation, financial standing and potentially their legal standing as well.

A corporation bears the burden of responsibility for its employees and their actions. By employing network security devices to monitor and restrict Internet activity, a corporation not only relieves a large measure of their burden, but also protects their interests on numerous fronts. Without such protection, a company is courting disaster and inviting scandal.

Saturday, March 28, 2009

Don’t Be Bugged - Get Bug Detectors

You are walking along, sweeping back and forth, area after area, searching. You are continuing searching when suddenly a sound begins to click, faster and faster. Is it a Geiger counter? No, it is your bug detector. That is right. If you suspect that someone is listening in on your private conversations, strategic development meetings, covert operations, or whatever your reason for secrecy might be, you can stop it instantly and for good with bug detectors.

These handy devices promise you peace of mind and are capable of detecting, locating, and verifying hidden transmitters regardless of where they might be. These work not just in your office or home, or only on your telephone, but even in or on your car.

You may be asking yourself what the difference is between detecting and verifying a hidden transmitter. Obviously, if you detect and locate a bug, you are verifying that you are being bugged, right? Well, verifying in this instance means something else entirely. Let us say that you are sweeping for bugs and the bug detectors you are using begin to squeal or vibrate, telling you that a bug is present. There is a possibility that what it is picking up is not a bug but an ordinary television or radio transmission.

You could drive yourself nuts trying to find a non-existent bug you believe is planted somewhere on your television or radio. But since you are also able to verify with your bug detectors, you will then know that it is not a bug but just a regular, non-threatening transmission.

Thursday, March 26, 2009

Avoiding Identity Theft

What's in a name? Possibly thousands of dollars. That's the word from law enforcement agents who say that Americans lose millions to identity theft each year.

The term "identity theft" refers to a crime in which a person steals your Social Security number or other private information. The criminal then uses that information to charge items or services on your credit or simply steal money from your bank account. The thieves often operate online, making it especially important to take precautions when surfing the Web.

A new book called "Geeks On Call Security and Privacy: 5-Minute Fixes" (Wiley, $14.95) could help you protect your identity. It offers expert advice on securing your computer as well as simple, step-by-step explanations of topics ranging from stopping viruses and spyware to backing up your data. The book explains these tips and others in detail:

Encrypt Your Computer Data

If your computer contains financial statements, credit card numbers, business documents, names and addresses of friends and family or other private information, consider using encryption software.

Social Security Numbers

Never use your Social Security number as a login on a Web site and do not give your Social Security number if an unsolicited e-mail requests it.

Avoid Automatic Logins

Some Web sites offer to save your user name and password so you can avoid the hassle of logging in over and over again. However, saving this information can make it easier for a thief to steal your identity.

Always Log Out

Before exiting an Internet account (online banking, bill pay, etc.), be sure to click the "Log Off" or "Log Out" button. This closes your session on the site and prevents someone from breaking into your account by clicking the back button on your Web browser.

Avoid Credit Card "Auto Save"

Most e-commerce Web sites allow you to store credit card numbers on their databases to make future transactions faster. Unfortunately, these databases are often targeted by hackers.

Wednesday, March 25, 2009

Where Spyware Lurks on the Internet

Spyware has to be the most talked about PC security threat of 2005. It has now surpassed the computer virus as the No. 1 menace to computer user both at home and in the enterprise. Despite efforts from Microsoft and independent security software companies, the spyware menace is set to continue through 2006 and beyond. The research firm Radicati Group expect worldwide anti-spyware revenue to surpass $1 billion by 2010.

There are numerous types of spyware with some more dangerous than others. At one end of the spectrum spyware pushes annoying ads to your computer as is usually referred as “Adware.” It is still spyware as the ads are generally pushed to you based on your surfing habits. A bad infection can also dramatically impact your computer’s performance as your desktop slowly gets overwhelmed with pop up adverts.

At the other end of the spectrum spyware programs can record what you do on your computer including individual key strokes. This information is then shared with a third party. This data is then sold to marketing companies or used to profit from. For example, the program may have captured your bank log-in details or credit card information.

Profit from these activities drives spyware development and deployment. According to anti-spyware vendor Webroot Inc advertising revenue generated from spyware is much more lucrative than trying to generate profit through Spam Email.

Here are the common ways spyware gets onto your computer:

• Bundled with free software like screensavers or P2P file sharing programs which you download. For example Kazaa, a P2P file-sharing application, installs adware onto a user’s computer even though it claims to contain “no spyware.” Waterfalls 3 from Screensaver.com installs spyware and Trojan horses. Examples are courtesy of a report from StopBadware.org’s website.
• Opening Spam email attachments.
• Being enticed into clicking on links in pop up adverts which then downloads spyware. These pop ups usually display messages to do with winning money or entering a special prize drawer.
• “Drive-by downloading” – this is when spyware is automatically downloaded onto your computer from the website you are surfing.

Earlier this year a report published by the University of Washington revealed categories of websites which are mostly like to host spyware or infect users through “drive-by downloads.” Their research revealed the following categories:

• Gaming sites
• Music download sites (I interpret this to mean “illegal” music sharing sites like dailymp3.com or where you can find P2P applications)
• Adult sites
• Celebrity sites
• Wallpaper / screensaver sites

Here are some tips and strategies to reduce the chance of spyware infection:

• Switch on your browser’s pop blocker.
• Install an anti-spyware tool with active protection which helps prevent infection in the first place.
• Keep Windows and other Microsoft applications like office up to date with the latest patches.
• Use SiteAdvisor (http://www.siteadvisor.com). This is a free plug-in for your browser which tells you whether a site is safe or not based on their testing. This is new software which is highly recommended.
• If you are a frequent visitor of the high risk categories please consider changing your surfing habits or at least making sure your system is fully protected.

Tuesday, March 24, 2009

5 Security Considerations When Coding

1. Input Checking

Always check user input to be sure that it is what you expected. Make sure it doesn’t contain characters or other data which may be treated in a special way by your program or any programs called by your program.This often involves checking for characters such as quotes, and checking for unusual input characters such as non-alphanumeric characters where a text string is expected. Often, these are a sign of an attack of some kind being attempted.

2.Range Checking

Always check the ranges when copying data, allocating memory or performing any operation which could potentially overflow. Some programming languages provide range-checked container access (such as the std::vector::at() in C++, but many programmers insist on using the unchecked array index [] notation. In addition, the use of functions such as strcpy() should be avoided in preference to strncpy(), which allows you to specify the maximum number of characters to copy. Similar versions of functions such as snprintf() as opposed to sprintf() and fgets() instead of gets() provide equivalent length-of-buffer specification. The use of such functions throughout your code should prevent buffer overflows. Even if your character string originates within the program, and you think you can get away with strcpy() because you know the length of the string, that doesn’t mean to say that you, or someone else, won’t change things in the future and allow the string to be specified in a configuration file, on the command-line, or from direct user input. Getting into the habit of range-checking everything should prevent a large number of security vulnerabilities in your software.

3.Principle Of Least Privileges

This is especially important if your program runs as root for any part of its runtime. Where possible, a program should drop any privileges it doesn’t need, and use the higher privileges for only those operations which require them. An example of this is the Postfix mailserver, which has a modular design allowing parts which require root privileges to be run distinctly from parts which do not. This form of privilege separation reduces the number of attack paths which lead to root privileges, and increases the security of the entire system because those few paths that remain can be analysed critically for security problems.

4.Don’t Race

A race condition is a situation where a program performs an operation in several steps, and an attacker has the chance to catch it between steps and alter the system state. An example would be a program which checks file permissions, then opens the file. Between the permission check the stat() call and the file open the fopen() call an attacker could change the file being opened by renaming another file to the original files name. In order to prevent this, fopen() the file first, and then use fstat(), which takes a file descriptor instead of a filename. Since a file descriptor always points to the file that was opened with fopen(), even if the filename is subsequently changed, the fstat() call will be guaranteed to be checking the permissions of the same file. Many other race conditions exist, and there are often ways to prevent them by carefully choosing the order of execution of certain functions.

5.Register Error Handlers

Many languages support the concept of a function which can be called when an error is detected, or the more flexible concept of exceptions. Make use of these to catch unexpected conditions and return to a safe point in the code, instead of blindly progressing in the hope that the user input won’t crash the program, or worse!

Monday, March 23, 2009

Background of Password cracking

Passwords to access computer systems are usually stored, in some form, in a database in order for the system to perform password verification. To enhance the privacy of passwords, the stored password verification data is generally produced by applying a one-way function to the password, possibly in combination with other available data. For simplicity of this discussion, when the one-way function does not incorporate a secret key, other than the password, we refer to the one way function employed as a hash and its output as a hashed password. Even though functions that create hashed passwords may be cryptographically secure, possession of a hashed password provides a quick way to verify guesses for the password by applying the function to each guess, and comparing the result to the verification data. The most commonly used hash functions can be computed rapidly and the attacker can do this repeatedly with different guesses until a valid match is found, meaning the plaintext password has been recovered.

The term password cracking is typically limited to recovery of one or more plaintext passwords from hashed passwords. Password cracking requires that an attacker can gain access to a hashed password, either by reading the password verification database or intercepting a hashed password sent over an open network, or has some other way to rapidly and without limit test if a guessed password is correct. Without the hashed password, the attacker can still attempt access to the computer system in question with guessed passwords. However well designed systems limit the number of failed access attempts and can alert administrators to trace the source of the attack if that quota is exceeded. With the hashed password, the attacker can work undetected, and if the attacker has obtained several hashed passwords, the chances for cracking at least one is quite high. There are also many other ways of obtaining passwords illicitly, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, timing attack, etc.. However, cracking usually designates a guessing attack.

Cracking may be combined with other techniques. For example, use of a hash-based challenge-response authentication method for password verification may provide a hashed password to an eavesdropper, who can then crack the password. A number of stronger cryptographic protocols exist that do not expose hashed-passwords during verification over a network, either by protecting them in transmission using a high-grade key, or by using a zero-knowledge password proof.

My Spyware Nightmare, Your Lesson

Have you asked yourself any of these questions lately?

1. Why is my brand new computer slowing down to a crawl?
2. Why is it taking so long to load a basic word processor?
3. Why do I have so many popups? Where are they coming from?
4. Why do I keep being sent to places I did not ask to go?
5. Where are these embarassing popups coming from? I never visit sites like that!

I did. I was ignorant. I was slow and it cost me a brand new computer. Here is my story.

A couple of years ago, we bought a new eMachine for my wife. She had just enrolled in school and needed something better for her school work. Prior to that, we had an older HP machine. I believe it was a pentium II. It worked pretty well, though a little slow. I wanted us to get another HP, but she wanted an eMachine. Her cousin had one and she thought it was good. I did not like eMachines a lot and did not think highly of them. She was bent on having one so we bought one.

With the arrival of the new computer, the HP was quickly abandoned. I was pretty much the only one that used it. Not because of my disdain for eMachine, but becasue the HP was more in a central location. Our three boys loved the new machine and spent quite some time on it. I was eventually won over to the eMachine and I must confess, it turned out to perform excellently well. It was good on speed and the resolution was great.

Several months down the road, I noticed how the new computer was slowing down. I knew in my mind it was the eMachine. They were no good. And then I thought it was the dial up connection. But I soon realized that it was also slow when I was offline. It was taking long to open up applications and even longer to load webpages. I also noticed there were strange windows openning up at the most awkward times. Some of the pages were to sites I would not ordinarily visit. May be the boys are going to places that we don't know about. As a concerned parent, I asked them and they promptly denied. I was still not sure they did'nt. They were teenagers.

As time passed, it became more difficult to do anything on the eMachine. We gradually migrated back to the HP and there was no immediate need to find out what was wrong with it.

Finally, it was time to act. I was ready to find out what the problem was. I started asking questions and doing querries on google. I was encouraged to get a good popup blockers. I did and it did not do much. That computer was far gone and corrupted. I had waited too long. I was not sure what was going on and did not know where to ask. The warrantee on the computer had also expired.

One afternoon, I turned the computer on to take another look and was greeted by a blank screen. The monitor had also quit I said to myself. Now I knew almost for sure it was the eMachine. They were really no good. My wife disagreed. But to be sure, I hooked the monitor up to the HP and it came alive. So it was'nt eMachine after all. I was a little embarrassed.

I reconnected the monitor and rebooted and was again faced by a blank screen. The following week, I took the cpu to a repair and they told me the computer was dameged beyond repair. I retrived it and took it to a sencond repairman and it never came back.

You know, lightening they say does not strike the same spot twice. But spyware is different. It can strike the same spot many times. Early 2005, I bought another computer, having out grown the HP. Months latter, I noticed the same exact symptons that ruined the eMachine. The slow down, the multiple popups, redirects to undesirable websites, they were all there. This time I did not wait. That afternoon I was frantic. I began searching for a quick answer. It was not until late that night that I found a product that worked for me. And once I found the right solution, spyware was no longer an issue to me.

Spyware can make your online experience a nightmare if you are not forward thinking about internet security. The good news is that there are plenty of products out there that can cure that effectively.

Sunday, March 22, 2009

How to Protect Your Files From a Computer Virus

How safe is your computer? Could you be in danger of getting a virus on your system? Just how real is the danger? What steps should you take if any?

While visiting with a one of my students, I became aware that her anti-virus software was over seventeen months old and had never been updated. Upon informing her that she should update her anti-virus software regularly, she was totally surprised. Furthermore she had no concept how essential this was to ensure her system's safety. Therefore I thought it wise to write about some of the precautions you should take to avoid becoming infected with a computer virus.

While there are many 'virus' hoaxes, and please do not pass any of these hoaxes on as these may actually contain viruses, computer viruses do pose a very real danger. Therefore I've listed a few preventative measures that you should take to ensure computer safety.

1. Do install an anti-virus software program and update it often as there are new viruses discovered everyday. I update my anti-virus database daily. At least weekly should be a goal. If you are not updating perpetually, it is like having an insurance policy and never paying the premiums. In no time at all it would be worthless.

2. Be wary of email from strangers. Never open an email with an attachment from a source that is unknown or suspicious. Virus containing emails can be very persuasive in the subject line. Do not let your curiosity be aroused.

I prefer an anti-virus program that has the ability to check all email sent and received. If you update it often, this should keep you safe, although nothing is 100% secure. There are good programs that offer a free version for personal use. These programs generally allow continual updates. Some may require that you register again at the end of year, but the software and updates will still be free.

Two such programs are:

AVG anti-virus, Free edition
http://grisoft.com

Free avast! 4 Home Edition
http://www.avast.com/eng/avast_4_home.html

Free Firewall & Antivirus
www.personalfirewall.comodo.com
For more options and reviews on programs you can do a search on google for free anti-virus.

3. Do exercise caution when downloading files from the Internet. Be sure to download from well known and reputable sources. Ascertain that your anti-virus software is set to scan files while you are downloading. I have that feature enabled in my anti-virus program and it scans all files when I am in the process of downloading, and it has on occasion prevented me from downloading a file that was infected or posed a potential danger. These programs work so take advantage of the security your anti-virus will provide by using all of the safety features.

4. New viruses creep upon a daily basis. It is important to back up your important files regularly. CD’s and DVD’s hold a large amount of information. Take advantage of this and store your valuable information and computer programs on these removable disks. In the event that a virus should ever invade your system and your files become corrupted you will be able to replace them with your backup copies.

5. Lastly apply the little rule, 'When in doubt do without'. If you are uncertain, whether it is with an unknown source in your email or a web site that offers a download, then best not to take a chance. No email message or free software is worth the damage to your computer files and the time and expense of repairing your PC. Do not be fooled, computer viruses do affect everyone.

The Internet offers us an array of software, services, entertainment and education that is beneficial. There is no reason to fear the web, it can be safe and secure. Yet it would be unrealistic to assume that there is no danger of computer viruses. There are unscrupulous persons who desire to do you harm. By observing these few guidelines you can minimize any threat of a virus attacking your computer.