Category: Computer Security

  • 5 Simple ways to keep your computer secure and virus free

    These simple tips will help you stay virus and spyware free, even if you're connected to the internet 24 hours a day.

    1. Protect yourself

    Good protection on the Internet these days consists of 3 components: anti-virus software, anti-spyware software and a firewall.

    Good virus protection doesn't need to cost you a fortune. You can get excellent free anti-virus software at www.grisoft.com. Even the professional version of their software is very affordable.

    For spyware protection, go to www.lavasoft.de and download Ad-Aware SE Personal, also free. This will zap the most common spyware and adware found on the Internet.

    As for a firewall, Windows XP ships with a decent enough firewall. Just make sure it is always enabled. Alternatively you can visit a site like www.download.com and search for Zone Alarm, which has an excellent free version.

    The most important thing to keep in mind is that you need to keep your anti-virus software up to date. An anti-virus program that uses definitions that are months old is just about useless.

    Update your anti-virus and anti-spyware software at least once a week.

    2. Stop opening every attachment you receive.

    Most of the devastating worms and viruses of recent times were distributed via email. These viruses feed on the curiosity and also the ignorance of a huge number of email users. People will get an email from fakename@weirdsuspiciousdomain and they'll just open whatever file is attached to it.

    If you don't know the sender, don't open the attachment – just delete it. It doesn't matter if the subject promises you'll see Britney Spears dancing nude on the kitchen table, just delete it.

    If the email is from someone you know, always scan any attachments first before downloading or opening them.

    If every email user in the world followed these simple guidelines the distribution of viruses via email will grind to a halt.

    3. Stay clear of pornographic and illegal software sites

    *I know, I know… Why on earth go on the Internet if you can't have your porn and download it too?!  There are safe Porn sites but we will not address those in this blog… sorry.. Fark has some pretty good links to decent smutt.*

    If you want to pick up viruses and spyware quickly, visit some pornographic web sites. One wrong click on a subtle little pop-up or security warning window (which you'll run into often on these type of sites) and you'll have infested yourself with trojan horses, spyware, dialers and other unfavorable software that could leave your computer wide open to further attacks.

    The same goes for web sites distributing software, serial codes and cracks illegally (warez).

    Simply put – keep out of the dark side of the web and the odds of keeping your computer clean shifts decidedly in your favor.

    4. Watch out what you download

    Spyware is embedded in a lot of software on the Internet – especially those related to ripping, converting and playing music and videos. That free MP3 player or DVD Ripper you just downloaded may have installed a bunch of harmful spyware without you even knowing about it.

    5. Keep yourself informed

    Major anti-virus software developers like Symantec and Grisoft updates their sites regularly with the latest virus alerts. Visit these sites frequently to keep yourself aware of what threats are doing the rounds and how to avoid them.

    Using these simple and software I have kept my computer virus-free for the past 3 years. It's not rocket science. Just stay alert, use some common sense and you too can stay bug free while still enjoying your Internet experience.

     

    Tips on Broadband Security –>

    http://elamb.blogharbor.com/blog/BroadbandInternetSecurity

    Get rid of Trojans Smithfraud/HWclock.exe

  • Defcon's Infamous Wall of Sheep

    One of my favorite traditions at the Defcon is the “Wall of
    Sheep.”  It displays all the “sheeple” that have not secured there
    systems yet feel compelled to get on the Defcons Wi-Fi. 
    During Defcon 11 one guy was there doing his
    taxes!!  Needless to say he was tripped naked and paraded
    around the conference like an apple stuffed Luau Pig.  At least
    they didn't display his Tax ID.       

    Take K. Rose's advice… If you're going to Defcon, don't turn on your laptop.

    read more | digg story

  • Alternative Knoppix Bootable CD Distros

    Some lesser known knoppix bootable linux cds. Give them a try!
    Auditor
    WarLinux
    Knoppix MAME
    Elive

    Are all listed and described.

    Also try WHAX/Whoppix

    read more | digg story

  • Using VNC & SSH

    How to use VNC along with SSH to remotely and securely access your computer desktop by way of tunneling.

    VNC is a huge vulnerability on a network without encryption. Particularly on medium to large networks with lots of users. I use it at home but don't see the need for encryption there.

    read more | digg story

  • Use Google To Find Passwords

    Google hackers have been doing this for a while now. Here is a tutorial on finding passwords using google. This could be used to secure your own web server.

    Security Professionals charged with protecting IT infrastrutures would do well to become the most aggressive hacker of their own networks. This would help them to proactively seek out new exploits on their network, webserver, or IS they protect.

    read more | digg story

  • Startup Aims To Overload Spammer Web Sites

    A startup security firm is taking the fight to spammers by enlisting end users to create what's called a Do-Not-Intrude registry whose purpose is to make it too painful for junk mailers to operate.

    This is MY kind of company!  I really despise spam.  My biggest problem is the Spam filth that is actual scams or malware that downloads to your computer.  This is a bigger problem than people realize.  Just look at that virus on those Micheal Jackson emails that nuked thousands of people.

    read more 

  • Secure RSS Syndication

    Solution for making your own private RSS Syndication using bloglines, encryption and Greasemonkey. 

    The way you'd use this is to make an RSS feed that you can access from anywhere.  Then encrypt it and use a Firefox script on Greasmonkey to decrypt it (at least thats the way I understand it).  The cool thing about it is that you could throw it right on pages with all relevent information across the web.  As soon as you updated it, it would reflect in your aggreggator.

    I could see this being used for my many network passwords, but not my accounts.  I'm a little to paranoid for that.

    read more 

  • Whax How to (formerly known as whoppix)

    The WHAX Live CD OS (formerly known as WHOPPIX) has a useful knowledgebase of growing information on how to use its very modular features.

    I notice a few people coming to my blog to find tutorials on WHAX/Whoppix, but where you really want to go is here:

    http://iwhax.net/modules/xoopsfaq/

    If there is something you want to know just ask the WHAX gurus on their interactive site.  The Whoppix webpage looked nice but the creators of this incredible tool made a briliant move in this new interactive, blog howto structure.

    If you Whax guys read this, I suggest getting some trackbacks.

    read more | digg story

  • Security+ vs. CISSP Part 1

    I took the Security+ certification test.  I didn't read any books but I did read a lot of test questions, went to a seminar sponsored by my local ISSA chapter and I've got a few years experience in all the Security+ domains.  After studying hard for a few weeks, I don't think that the test was that hard.  If I had not been prepared then I can see how it might have been difficult as there are some pretty specific questions on things I did four years ago.

    The Security+ is NOTHING compared to the CISSP.  I've yet to take the actual CISSP cert test, but as I've been studying it is VERY clear that these tests are from different planets.  It is like comparing the Comptia N+ to cisco's CCNP or CCIE… o.k. maybe not CCIE, but CCNP for sure.

    I've been studying to take the CISSP on and off for about a year due to a fairly full plate.  I plan on taking the test in the next few months so I've started reading up on some practice questions.  My orginal plan was to get a Security+ cert so that I could prepare for the CISSP.  As I've been reading the practice questions on CISSP I'm finding that the Security+ is simply not robust enough to even come close to helping me study for the CISSP.

    Once I take the actual CISSP I'll be able to make a better assessment, though.

    One of the most helpful items I found on was a Security+ cheat sheet.  It is a very concentrated view of all five security+ domains and makes for a great study reference. 

     

  • IE7 will have antivirus/anti-phishing tech built in

    Microsoft has detailed its forthcoming privacy and security plans, which incorporates antivirus technology from recently acquired Sybari, and enhanced anti-phishing software. “Anti-phishing will definitely be built in to IE 7,” said Brendon Lynch, senior privacy strategist at Microsoft.

    Sounds cool.  I'm really looking forward to the built in RSS features of IE7. 

    read more | digg story