Archive for January, 2007

Beware the Free Public Hotspot

Posted in All Posts, Email Security, Online Security, Privacy, Safe e-Commerce, Wireless Network Security on January 26th, 2007

Free Wireless hotspots are all over the place.   They can be found in most any populated area. Tempting aren’t they?

Just beware. And be aware. They can be dangerous.

  • Any and all data that you send over many of these networks is vulnerable to interception.
  • Check your email, and some crooks may now have your email server address, user name and password,and send tons of spam in your name.
  • Log onto your office network. And tomorrow, some creep logs in with your user name and password.
  • Check your bank account? You may find it empty.

We don’t mean to alarm you.  But it’s really worth knowing that using a wireless network can be risky.  “Somebody” may be logging every bit of traffic.  And that “somebody” may not have your best interests at heart.  

But wait, there’s more: Even if the network itself is safe, it is all too easy for somebody to impersonate it and rout all your traffic through a proxy that logs all your surfing. So be careful out there.

Practice safe computing!

Sources:

http://tinyurl.com/3b58ps

http://tinyurl.com/32368q

Beware the Storm Worm

Posted in All Posts, Email Security, Exploits, Malware, Online Security, Root kits, Scams, Security Tools, Wired Network Security, Wireless Network Security on January 22nd, 2007

A massive storm that swept across Europe last week…

And then in it’s wake was a storm across the Internet - in the form a series of virus infected emails.

And reference our previous Post, clearly there is a serious lacking of “Street Smarts” among computer users because this virus spread like wildfire.  Check out the F-Secure video post on YouTube, and see for yourself.

All users are advised to update their anti-virus programs and use caution when opening email, and especially email that refers to current events in the news* and induces the recipient to open the attachment.  Some examples:

230 dead as storm batters Europe.
A killer at 11, he’s free at 21 and…
British Muslims Genocide
Naked teens attack home director.
U.S. Secretary of State Condoleezza…
  Russian missle shot down Chinese satellite
  Russian missle shot down USA aircraft
  Russian missle shot down USA satellite
  Chinese missile shot down USA aircraft
  Chinese missile shot down USA satellite
  Sadam Hussein alive!
  Sadam Hussein safe and sound!
  Radical Muslim drinking enemies’ blood.
  U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel
  U.S. Southwest braces for another winter blast. More then 1000 people are dead.
  Venezuelan leader: “Let’s the War beginning”.
  Fidel Castro dead.
  Hugo Chavez dead.

The virus package that this email can load on your computer is nasty.  But users of infected computers may not even be aware that they are infected
Please note that this series of virus infected emails has a variety of subject lines and may contain several different attachments.

For more information, check out the F-Secure Blog.  They have posted a video of the infection spreading across the globe, and also provide detailed information as to the contents of this virus infected series of email.

* The latest variants have branches out into any number of subject lines:

  So in Love
  Happy World Religion Day!
  Most Beautiful Girl
  Someone at Last
  I Believe
  The Dance of Love
  The Miracle of Love
  All For You
  Vacation Love
  I am Complete
  Wrapped Up
  Moonlit Waterfall
  A Little (sex) Card
  A Special Kiss
  Hugging My Pillow
  Safe and Sound
  You’re Soo kissable
  A Romantic Place
  Breakfast in Bed Coupon
  For You
  I Love You So
  Safe and Sound
  Want to Meet?
  We Are Different
  We Have Walked
  You Asked Me Why

Please note that this virus may also have a rootkit component that most anti-virus programs are not able to detect or remove.  F-Secure’s Blacklight rootkit detector can detect and remove this rootkit.  This tool should be run on any computer that has become infected.  Blacklight can be downloaded from F-Secure via the following link: 

http://www.f-secure.com/blacklight/

- Practice Safe Computing

Street Smarts

Posted in All Posts, Online Security, Safe e-Commerce on January 21st, 2007

Street smarts, also known as being “streetwise”, is defined as follows:

Possessing the skills and attitudes necessary to survive in a difficult or dangerous situation or environment.

Users of the Internet need to develop streetwise skills and attitudes, and surf defensively.

This is not to say that the Internet should be avoided entirely.  The Internet is a tremendous information, communication and business resource, but more and more, the Internet has become an environment that requires “Street Smarts”.

An good article on the subject:

AVG Free Edition is Alive and Well!

Posted in All Posts, Anti-Malware Tools, Email Security, Exploits, Security Tools, Updates, Wired Network Security, Wireless Network Security on January 19th, 2007

Lots of folks seem to believe the that the free version of AVG Anti-Virus is no longer available.  This is not true.

This is true:

  1. AVG Anti-Virus Free Edition is alive and well.
  2. Product support (virus signature updates) for AVG Anti-Virus Free Edition, version 7.1, will be ending February 18, 2007. 
  3. There is a new version of AVG Anti-Virus Free Edition, version 7.5.
  4. Customers should upgrade to version 7.5 before February 18, 2007.
  5. AVG Anti-Virus Free Edition, version 7.5, will continue to receive virus signature updates after February 18.
  6. AVG Anti-Virus Free Edition will continue to be free.
  7. Maybe that is why it is named AVG Anti-Virus Free Edition.

Yes, AVG Anti-Virus Free Edition, version 7.5. is alive and well and can be found at the following link:

http://free.grisoft.com/

Please note that AVG Anti-Virus Free is for private, non-commercial, single home computer use only.

 

Tools for Internet Privacy

Posted in All Posts, Email Security, Online Security, Privacy, Security Tools on January 15th, 2007

The Electronic Privacy Information Center provides an excellent,  comprehensive list of tools to help secure personal privacy on the Internet.  The list may be found at:

 http://www.epic.org/privacy/tools.html

 

How a Password Guessing Program Works

Posted in All Posts, Online Security, Safe e-Commerce on January 12th, 2007

Ever wonder how a password guessing program works?  

Well, these clever little beasts can test thousands of passwords a second.   Unfortunately, they are remarkably successful. 

Yet, if we understand the kind of passwords they can most easily crack, we may get a better understanding of how to make stronger passwords, and counter these beasts.

Bruce Schneier, one of the most respected experts in the world of computer security has written great little article on this subject.  We highly recommend it: 

Secure Passwords Keep You Safer

Check for Updates in One Feld Swoop

Posted in All Posts, Anti-Malware Tools, Updates on January 5th, 2007

The Importance of Updates: 

We’re getting the idea.  Updates are important.  And increasingly, updates are more likely to be for security reasons than for new features and functionality.  But how do we keep up with all these updates?  Well, one can systematically open each program in turn, check for updates if there is a means do do so.  Or, one can visit the creators web site and see if there are new updates.

But now, thanks for Secunia, there is a new way to check for updates in one feld swoop.

http://secunia.com/software_inspector/

_____________________________________________________________________________________________________________

L10 Web Stats Reporter 3.15 L10 Hit Counter - Free Web Counters
LevelTen Web Design Company - Professional Flash & Website Designers