Category: Internet and Information Technology Security

  • McAfee Reveals 'OneCare' Competitor, Falcon

    McAfee announced today an all-in-one security subscription service codenamed Falcon. Falcon will contain all major security suite components as well as PC backup and tune-up tools. It's essentially a competitor to Microsoft's Windows OneCare, expected soon, and Symantec's Genesis (also a codename), due out this fall.

    Symantec has a lawsuit against Microsoft based on allegde “misappropiation of intellectual property.”

    <sarcasm>

    It seems so uncharacteristic to steal ideas from other companies:    Netscape Navigator
    Eudora Pro
    Stacker (as mentioned above)
    Quarterdeck QEMM and Max386

    </sarcasm>

    What blows my mind is how Microsoft continues to get away with this. 

    Microsoft Innovator's Copy & Conquer

    read more | digg story

  • 18 Days of Reckless Computing

    Someone over at wired gives tests his new Dell to see how many viruses and how much malware it takes to get the Geek Squad to call it a total loss.

    read more | digg story

  • 10 Security Suite Reviews : Who's Got Your Back

    All-in-One Security

    Suites of antivirus, antispyware, and firewall software can provide convenient, solid protection against today's worst threats. Our tests of ten contenders show who's got your back.

    read more | digg story

  • Computer Viruses Monitored via Dynamic Worldmap

    You'll be able to view Previous Hour, Previous Day, Previous Month, This Year, and Previous Year. Color Coding has 6 Ranges (No Data, Quiet, Low, Medium, High, and Epidemic)

    read more | digg story

  • How to get Malware/Virus/Trojans on your Home Windows computer:

    1) Use Window 9x/2000/XP out of the box DO NOT bother to reconfigure it
      

    Don't create any login accounts with strong passwords
    Do all work from the adminstrator account (Windows does this out automatically  so   don't do anything)
    Do not bother with patches no matter how critical (Windows will prompt you to update, just ignore it)
    Don't disable the guest account
    Don't change the name of default administrator account
    Enable as many network protocols as you can

     

    2) Use Internet Explorer

    If you want your system to get infected with all kinds of malware DO NOT use Firefox or anytype of pop up blockers
    When you use IE, don't increase the security under: Tools | Internet Options | Security tab, just leave it as is
    Ensure all Java and ASP scripting languages are enabled, allowing other computers to load software on your computer remotely
    Never patch Internet Explorer

    3) Connect directly to the Internet

    Do not use any kind of firewall 
    Do not use Network Adress Translation (which will hide your IP adress)
    Do not load SP2 for Window XP
      

    4) Surf the deadliest sites with no protection

    Surf Serial/Crack/Warez sites and always completely trust their sites
    Porn sites with no protection
    Screen Saver sites
    “hacker sites”  not all hackers sites just “black hats” and script kiddie type sites
    Find dark IRCs
      

    5) Behavior that will help you get your system infected.

    Download Screen Savers from site you are not sure about
    Open emails from people you don't know
    If you get a Security Warning that says “Do you want to download XXXXPROCUT NAMEXXX..” Don't even bother reading the rest just click yes.
      

    6) Software that is more than likely infected

    Tools bars that automatically download without your permission
    Kazaa and some other free P2P tools

     

    List of Tools for faster Infection:

    Internet Explorer  (Firefox can affectively block malware)
    Broadband/DSL (use of a firewall using Network Adress Translation will hide you system)
    Windows 9.x/2k/XP (open source OSes such as Linux are less likely to be hacked)

     

  • OpenVPN

    OpenVPN is a full-featured SSL VPN solution which can accomodate a wide range of configurations, including remote access, site-to-site VPNs, WiFi security, and enterprise-scale remote access solutions with load balancing, failover, and fine-grained access-controls.

    read more | digg story

  • PS Guard Removal

    PS Guard is viscious scareware that loads itself each time you attempt
    to unistall it.  It is malware that claims to be malware
    remover.  It disables your Task Manager, informs you that your
    system is infected and doesn't allow you to exit from it while it scans
    your computer for viruses.

    Removing PS Guard
    it is a bit tricky.  Adaware and Hijack this will do nothing to
    remove it.  Noahdfear over at GeekstoGo.com wrote a sweet little
    script to remove it called smitrem.  It does the trick in removing PS Guard

    I picked it up at some Russian warez site on my Honeypot sytem.

  • Windows Vista has More Security Features

    Windows seems to be taking security billions of dollars more serious.  This is very exciting.  I like Windows 2000/XP but the security is a major conscern.  While I don't think Vista will be able to beat up on Unix, Its great that it will be more secure. 

    Some of Windows Vista's Security Features include:

    Least-Priviledge User.  Previous implementations of Windows are shipped out with no default security features.  This is the reason most people surf with an Admin account.  Vista will have User Account Protection which will restrict common users to the following:

  • Laptop users will be able to set a WEP key to attach to a   home wireless network
  • Users will be able to install printer drivers
  • Users will be able to download and install updates
  • VPN and dial-up connections can be created and established
  • Running most applications  
  • Built in Anti-Virus and Firewall.  Windows Vista will have the ability to clean virus from the system.  So there may be less of a need for tools such as Adaware and Hijackthis.  Although I suspect some third party tools will still be necessary.

    The best thing I've read so far about the comming Vista security is the principles behind the Vista design:

    According to Debra Shinder's article at WindowSecurity.com

    Last week at the MVP global summit in Redmond, I had the opportunity to hear from a number of Microsoft insiders, the guys who actually wrote the code, about their goals and philosophy in creating the new OS and included components such as Internet Explorer 7.0. I was encouraged by what I heard: defense in depth was a concept that kept coming up over and over again. Multi-layered security is the only way to provide real protection, and MS’s commitment to making fundamental changes in the architecture to support that type of protection will give Vista a big security edge over older Windows operating systems.

     

    Resources:

    Windows Vista Principle of Least Privileges.  – Derek Melber

    First Look at Windows Vista: Security at Last? – Debra Shinder

     

  • Yet another university hacked for personal records

    College networks are always getting owned.  Why is that?  You'd think that these haven for some of the greatest developing minds in the country would be like digital fortresses with a battalion of young Internet hardened GEEKS patroling the college data 24/7.

    This is a sign that even though security awareness has risen people still are not taking it seriously. 

    POMONA – Computer hackers added Cal Poly Pomona to a growing list of schools from which personal information has been accessed illegally. Notification went out to 31,077 people Thursday that their records might have been stolen after Cal Poly Pomona discovered two computer servers were compromised in late June…

    read more | digg story

  • Experts: Computer Crime Down But Caution Still Needed

    CSI/FBI Computer Crime and Security Survey, Richardson noted that the average loss per cybercrime incident in 2005 was about US$250,000. That compares to $500,000 in 2004 and more than $3 million in 2001

    I guess Computer Crime has gone up comparing the begining of the year to the end of the year but overall more people (especially companies) are taking security much more seriously.  And it is about time, but industry security still has a ways to go… home security has barely started.

    read more | digg story