Norton launched a facebook security app that scans your news feeds and identifies URLs containing security risks such as phishing sites, malicious downloads and links to unsafe external sites. With this application, you can easily see which links in your News Feed are unsafe for you or your friends to click on. From the scan results page you can go through detailed feed analysis.
Showing posts with label SECURITY. Show all posts
Showing posts with label SECURITY. Show all posts
Thursday, 9 February 2012
Scan Your Facebook Account With Norton
Norton launched a facebook security app that scans your news feeds and identifies URLs containing security risks such as phishing sites, malicious downloads and links to unsafe external sites. With this application, you can easily see which links in your News Feed are unsafe for you or your friends to click on. From the scan results page you can go through detailed feed analysis.
Saturday, 7 January 2012
Worm Steals 45000 Facebook Logins - How to protect your account
A computer worm has stolen more than 45,000 Facebook login credentials, leaving users wonder how they can protect their accounts and personal info from future cyber attacks.
According to Israeli security management Web site Seculert, a "Ramnit" virus stole the login data for 45,000 Facebook users in the United Kingdom and France.
"Recently, our research lab identified a completely new 'financial' Ramnit variant aimed at stealing Facebook login credentials. Since the Ramnit Facebook C&C URL is visible and accessible it was fairly straightforward to detect that over 45,000 Facebook login credentials have been stolen worldwide, mostly from users in the United Kingdom and France," Seculert said on its company Web site.
The stolen credentials were used to spread the virus to other friends and to even attack the victim's other web-based services, as many users use the same passwords for other services like their e-mail accounts and other social media sites.
According to Microsoft, the Ramnit virus is "a multi-component malware family which infects Windows executable as well as HTML files" in addition to stealing stored FTP credentials and cookies from Web browsing.
Ramnit, according to PC World, is a two-year-old worm that has become more of a threat since it recently began to use borrowed code from malware Zeus, infecting about 800,000 machines worldwide in the past few months.
Seculert said it gave all pertinent data regarding the Ramnit virus to Facebook, including all stolen credentials found on the servers.
"Our security experts have reviewed the data, and while the majority of the information was out of date, we have initiated remedial steps for all affected users to ensure the security of their accounts," a Facebook representative told ZD Net.
"Thus far, we have not seen the virus propagating on Facebook itself, but have begun working with our external partners to add protections to our antivirus systems to help users secure their devices."
While social networks have the power to virally transfer information and communicate with others on a large scale, viruses can spread just as fast as sending a simple Hello to a friend. So how do you protect yourself and secure yourself from harmful viruses like the Ramnit, which anti-virus software Symantec reported accounted for 17.3 of all malicious software infections?
Facebook said while the social networking Web site is currently adding additional antivirus software protection, users should never click on any strange links or tagged posts from untrusted sources. Facebook also recommended reporting suspicious activity directly to Facebook security and to join the Facebook Security page for the most up-to-date security updates about potential threats and viruses.
Also, Web users should be reminded to vary passwords, rather than having the same password for all Web services, and changing them frequently.
For More Details: Click Here
"Recently, our research lab identified a completely new 'financial' Ramnit variant aimed at stealing Facebook login credentials. Since the Ramnit Facebook C&C URL is visible and accessible it was fairly straightforward to detect that over 45,000 Facebook login credentials have been stolen worldwide, mostly from users in the United Kingdom and France," Seculert said on its company Web site.
The stolen credentials were used to spread the virus to other friends and to even attack the victim's other web-based services, as many users use the same passwords for other services like their e-mail accounts and other social media sites.
According to Microsoft, the Ramnit virus is "a multi-component malware family which infects Windows executable as well as HTML files" in addition to stealing stored FTP credentials and cookies from Web browsing.
Ramnit, according to PC World, is a two-year-old worm that has become more of a threat since it recently began to use borrowed code from malware Zeus, infecting about 800,000 machines worldwide in the past few months.
Seculert said it gave all pertinent data regarding the Ramnit virus to Facebook, including all stolen credentials found on the servers.
"Our security experts have reviewed the data, and while the majority of the information was out of date, we have initiated remedial steps for all affected users to ensure the security of their accounts," a Facebook representative told ZD Net.
"Thus far, we have not seen the virus propagating on Facebook itself, but have begun working with our external partners to add protections to our antivirus systems to help users secure their devices."
While social networks have the power to virally transfer information and communicate with others on a large scale, viruses can spread just as fast as sending a simple Hello to a friend. So how do you protect yourself and secure yourself from harmful viruses like the Ramnit, which anti-virus software Symantec reported accounted for 17.3 of all malicious software infections?
Facebook said while the social networking Web site is currently adding additional antivirus software protection, users should never click on any strange links or tagged posts from untrusted sources. Facebook also recommended reporting suspicious activity directly to Facebook security and to join the Facebook Security page for the most up-to-date security updates about potential threats and viruses.
Also, Web users should be reminded to vary passwords, rather than having the same password for all Web services, and changing them frequently.
For More Details: Click Here
Tuesday, 22 November 2011
11 Tips for Safe Online Shopping
Let's face it, there's every reason in the world to shop online. The bargains are there. The selection is mind-boggling. The shopping is secure. Shipping is fast. Even returns are pretty easy, with the right e-tailers. Shopping has never been easier or more convenient for consumers.
But what about the bad guys who lay in wait? IID's Third Quarter eCrime Report for 2011 indicates that use of phishing attacks (where thieves attempt to swindle you out of your sign-in credentials and even credit card info by pretending to be a real website, or even an online bank) is down, as much as eight percent since the second quarter and 11 percent since the third quarter of last year. That's great news—except the same report says sites with malware (malicious code aimed at compromising your privacy) has increased by 89 percent since the second quarter.
Stay calm. While somewhat alarming, these stats should not keep you from shopping online. You simply need some common sense and practical advice. Follow these basic guidelines and you can shop online with confidence. Here are 11 tips for staying safe online, so you can start checking off items on that holiday shopping list.
1. Use Familiar Websites
Start at a trusted site rather than shopping with a search engine. Search results can be rigged to lead you astray, especially when you drift past the first few pages of links. If you know the site, chances are it's less likely to be a rip off. We all know Amazon.com and that it carries everything under the sun; likewise, just about every major retail outlet has an online store, from Target to Best Buy to Home Depot. Beware of misspellings or sites using a different top-level domain (.net instead of .com, for example)—those are the oldest tricks in the book. Yes, the sales on these sites might look enticing, but that's how they trick you into giving up your info.
Start at a trusted site rather than shopping with a search engine. Search results can be rigged to lead you astray, especially when you drift past the first few pages of links. If you know the site, chances are it's less likely to be a rip off. We all know Amazon.com and that it carries everything under the sun; likewise, just about every major retail outlet has an online store, from Target to Best Buy to Home Depot. Beware of misspellings or sites using a different top-level domain (.net instead of .com, for example)—those are the oldest tricks in the book. Yes, the sales on these sites might look enticing, but that's how they trick you into giving up your info.
2. Look for the Lock
Never ever, ever buy anything online using your credit card from a site that doesn't have SSL (secure sockets layer) encryption installed—at the very least. You'll know if the site has SSL because the URL for the site will start with HTTPS:// (instead of just HTTP://). An icon of a locked padlock will appear, typically in the status bar at the bottom of your web browser, or right next to the URL in the address bar. It depends on your browser.
Never ever, ever buy anything online using your credit card from a site that doesn't have SSL (secure sockets layer) encryption installed—at the very least. You'll know if the site has SSL because the URL for the site will start with HTTPS:// (instead of just HTTP://). An icon of a locked padlock will appear, typically in the status bar at the bottom of your web browser, or right next to the URL in the address bar. It depends on your browser.
Never, ever give anyone your credit card over email. Ever.
3. Don't Tell All
No online shopping store needs your social security number or your birthday to do business. However, if crooks get them, combined with your credit card number for purchases, they can do a lot of damage. The more they know, the easier it is to steal your identity. When possible, default to giving up the least amount of information.
No online shopping store needs your social security number or your birthday to do business. However, if crooks get them, combined with your credit card number for purchases, they can do a lot of damage. The more they know, the easier it is to steal your identity. When possible, default to giving up the least amount of information.
4. Check Statements
Don't wait for your bill to come at the end of the month. Go online regularly during the holiday season and look at electronic statements for your credit card, debit card, and checking accounts. Make sure you don't see any fraudulent charges, even originating from sites like PayPal. (After all, there's more than one way to get to your money.)
Don't wait for your bill to come at the end of the month. Go online regularly during the holiday season and look at electronic statements for your credit card, debit card, and checking accounts. Make sure you don't see any fraudulent charges, even originating from sites like PayPal. (After all, there's more than one way to get to your money.)
If you do see something wrong, pick up the phone to address the matter quickly. In the case of credit cards, pay the bill only once you know all your charges are accurate. You have 30 days to notify the bank or card issuer of problems, however; after that, you might be liable for the charges anyway.
5. Inoculate Your PC
Swindlers don't just sit around waiting for you to give them data; sometimes they give you a little something extra to help things along. You need to protect against malware with regular updates to your anti-virus program. PCMag recommends Webroot SecureAnywhere Antivirus (4.5 stars, Editors' Choice, $39.95 direct), which has extras to help fight ID theft, or at the very least the free Ad-Aware Free Internet Security 9.0 (4.5 stars, Editors' Choice).
Swindlers don't just sit around waiting for you to give them data; sometimes they give you a little something extra to help things along. You need to protect against malware with regular updates to your anti-virus program. PCMag recommends Webroot SecureAnywhere Antivirus (4.5 stars, Editors' Choice, $39.95 direct), which has extras to help fight ID theft, or at the very least the free Ad-Aware Free Internet Security 9.0 (4.5 stars, Editors' Choice).
6. Use Strong Passwords
We like to beat this dead horse about making sure to utilize uncrackable passwords, but it's never more important than when banking and shopping online. Our tips for creating a unique password can come in handy during a time of year when shopping around probably means creating new accounts on all sorts of e-commerce sites.
We like to beat this dead horse about making sure to utilize uncrackable passwords, but it's never more important than when banking and shopping online. Our tips for creating a unique password can come in handy during a time of year when shopping around probably means creating new accounts on all sorts of e-commerce sites.
7. Think Mobile
The National Retail Federation says that 5.7 percent of adults will use their mobile devices to do comparison shopping before making a purchase. (And 32.1 percent will comparison shop online with a computer, as well.) There's no real need to be any more nervous about shopping on a mobile device than online. The trick is to use apps provided directly by the retailers, like Amazon, Target, etc. Use the apps to find what you want and then make the purchase directly, without going to the store or the website.
8. Avoid Public Terminals
Hopefully we don't have to tell you it's a bad idea to use a public computer to make purchases, but we still will. If you do, just remember to log out every time you use a public terminal, even if you were just checking email.
What about using your own laptop to shop while you're out? It's one thing to hand over a credit card to get swiped at the checkout, but when you must enter the number and expiration date on a website while sitting in a public cafe, you're giving an over-the-shoulder snooper plenty of time to see the goods. At the very least, think like a gangster: Sit in the back, facing the door.
9. Privatize Your Wi-Fi
If you do decide to go out with the laptop to shop, you'll need a Wi-Fi connection. Only use the wireless if you access the Web over a virtual private network (VPN) connection. If you don't get one from your employer, you can set up a free one with AnchorFree Hotspot Shield, if you're willing to put up with the ads, or pay $4.99 a month or $44.99 a year to skip the ads. There's even an iOS app version of Hotspot Shield, but that will cost you $.99 per month or $9.99 a year after the first seven days.
By the way, now is not a good time to try out a hotspot you're unfamiliar with. Stick to known networks, even if they're free, like those found at Starbucks or Barnes & Noble stores that is powered by AT&T. Look for the network named "attwifi," then open a browser to click into the "walled garden" to get final access. You can also find free Wi-Fi at McDonalds, Panera Bread, and FedEx Office locations, not to mention libraries and local cafes.
10. Count the Cards
Gift cards are the most requested holiday gift every year, and this year will be no exception. Stick to the source when you buy one; scammers like to auction off gift cards on sites like eBay with little or no funds on them.
11. Know What's Too Good to Be True
Once again, McAfee has compiled a Twelve Scams of Christmas list, all things to be aware of while shopping. The "coupon scam" offers of a free product with purchase, in particular an iPad (a very coveted gadget at any holiday) or even holiday job offers. Many of these "offers" will come in via social media. Beware even of your friends, who might innocently forward such a thing. Be very wary even if you get a message from friend claiming he or she has been robbed, especially a friend overseas looking for money to be wire transferred, unless you absolutely can confirm it by talking to him or her personally. Skepticism in most cases can go a long way toward saving you from a stolen card number.
The National Retail Federation says that 5.7 percent of adults will use their mobile devices to do comparison shopping before making a purchase. (And 32.1 percent will comparison shop online with a computer, as well.) There's no real need to be any more nervous about shopping on a mobile device than online. The trick is to use apps provided directly by the retailers, like Amazon, Target, etc. Use the apps to find what you want and then make the purchase directly, without going to the store or the website.
8. Avoid Public Terminals
Hopefully we don't have to tell you it's a bad idea to use a public computer to make purchases, but we still will. If you do, just remember to log out every time you use a public terminal, even if you were just checking email.
What about using your own laptop to shop while you're out? It's one thing to hand over a credit card to get swiped at the checkout, but when you must enter the number and expiration date on a website while sitting in a public cafe, you're giving an over-the-shoulder snooper plenty of time to see the goods. At the very least, think like a gangster: Sit in the back, facing the door.
9. Privatize Your Wi-Fi
If you do decide to go out with the laptop to shop, you'll need a Wi-Fi connection. Only use the wireless if you access the Web over a virtual private network (VPN) connection. If you don't get one from your employer, you can set up a free one with AnchorFree Hotspot Shield, if you're willing to put up with the ads, or pay $4.99 a month or $44.99 a year to skip the ads. There's even an iOS app version of Hotspot Shield, but that will cost you $.99 per month or $9.99 a year after the first seven days.
By the way, now is not a good time to try out a hotspot you're unfamiliar with. Stick to known networks, even if they're free, like those found at Starbucks or Barnes & Noble stores that is powered by AT&T. Look for the network named "attwifi," then open a browser to click into the "walled garden" to get final access. You can also find free Wi-Fi at McDonalds, Panera Bread, and FedEx Office locations, not to mention libraries and local cafes.
10. Count the Cards
Gift cards are the most requested holiday gift every year, and this year will be no exception. Stick to the source when you buy one; scammers like to auction off gift cards on sites like eBay with little or no funds on them.
11. Know What's Too Good to Be True
Once again, McAfee has compiled a Twelve Scams of Christmas list, all things to be aware of while shopping. The "coupon scam" offers of a free product with purchase, in particular an iPad (a very coveted gadget at any holiday) or even holiday job offers. Many of these "offers" will come in via social media. Beware even of your friends, who might innocently forward such a thing. Be very wary even if you get a message from friend claiming he or she has been robbed, especially a friend overseas looking for money to be wire transferred, unless you absolutely can confirm it by talking to him or her personally. Skepticism in most cases can go a long way toward saving you from a stolen card number.
Monday, 21 November 2011
The 12 Most Vulnerable Smartphones
How vulnerable is your smartphone to malware attacks? Android is by far the most targeted mobile operating system, but some popular Android phones made by Samsung, HTC, and Motorola, fare a lot worse than others.
Bit9, an enterprise-oriented security vendor, ranked the 12 most vulnerable cell phones (the "dirty dozen") based on how dated its software is out of the box. Android fragmentation is well documented, but your average cell phone user probably doesn’t care if he or she’s on Android 2.3 or Android 2.3.7. Functionally, the versions are similar.
However security-wise, it matters. A lot. For instance if a malicious app breaches an older version of Android, Google patches the vulnerability and releases an incremental update so that app can never exploit your phone again. Then it’s up to the cell phone operator to send your phone that update.
The timing of when you get these updates depends upon your cell phone operator and cell phone manufacturer, rather than Google, which is fundamentally different from how PC security is distributed (it would be akin to buying a PC from Dell and relying on Dell to coordinate with your home Internet provider, instead of Microsoft, to update your Windows software).
Unfortunately, not every Android phone gets updated to the latest version at the same time; pundits say carriers have no economic incentive to send updates to old or unpopular phones.
As a result, according to Google, 56 percent of Android smartphones are stuck on the 18-month old Android 2.3 Froyo, or older versions.
“We need to put pressure on the carriers. Why are they alone responsible for updating your security?” Harry Sverdlove, CTO of Bit9, told PCMag.
Honorable Mention: Apple iPhone 4
Apple's iOS is less fragmented because Apple retains full control over when it releases its software update. But fragmentation still exists, because newer versions of iOS either don’t work or perform uber slowly on models that are over two years old. Others iPhone owners are simply turned off by slow download speeds or excessively large files. Lookout Mobile recently discovered that 30 percent of iPhone users don’t download the latest version of iOS when it comes out, and therefore miss out on time-sensitive iOS patches.
As a result, Bit9 gave iPhone 4 an honorable mention.
Bit9’s “dirty dozen”:
1. Samsung Galaxy Mini (T-Mobile)
2. HTC Desire (U.S. Cellular)
3. Sony Ericsson Xperia X10 (AT&T)
4. Sanyo Zio (Sprint, Cricket Wireless)
5. HTC Wildfire (T-Mobile)
6. Samsung Epic 4G
7. LG Optimus S (Sprint)
8. Samsung Galaxy S (T-Mobile)
9. Motorola Droid X
10. LG Optimus One
11. Motorola Droid 2
12. HTC Evo 4G
BYOD (Bring Your Own Device), but not an Android!
Bit9’s findings may be preaching to the choir here, but its study is really aimed towards business workers who are ditching their BlackBerries for other popular operating systems—in droves. This week, one study claimed iPhone has surpassed BlackBerry as the most popular smartphone used in the office. But Bit9 and PCMag’s networking analyst Samara Lynn still believe BlackBerry is “tops for IT,” because it uses an enterprise server that gives companies full control over issuing updates.
As mobile malware matures, the targets will inevitably grow bigger and more lucrative.
“We’re going see more and more corporate attacks on smartphones, more spear phishing, more targeted email attacks. Given the landscape, it’s a ripe field that’s growing faster than the security itself,” said Sverdlove.
Saturday, 19 November 2011
Back Up Your Facebook Account Data
Facebook is a social media platform. As we all know some anti-social people or groups of people may attack your privacy and try to hack your computer. It is not always as safe as we think. we hear many threats, cases of social media hacking and attack on privacy. There are many threats coming up and there are rumors of destroying your Facebook accounts etc. We all know that facebook will not allow this to happen and keep all the visitors safe. There is an option in facebook where you can download all your facebook data including your pictures, videos, contact details, status updates, friends, groups etc. It is always safe to keep a back up of all your facebook data. Facebook permits you to download all your facebook data in a zip file and keep them safe with you all.
Many of you may not be knowing how to download and save all your facebook data in your personal computer. It is very easy to download all your data and keep them safe with you. Facebook makes it very easy so that users don’t have to face any technical trouble. It may take long time if data is too huge in size. Here is the step by step guidance for you with photographs that how can you download ans save your facebook data in your personal computer.
How Exactly You Do It
Go to your account setting (upper right corner of your home screen)
There will be a link in very small font showing ” Download a Copy of your Facebook Data” Click there.
A new page will open and show you in a Green Box “Start my Archive”
Click that. Your download will start and wait till it gets finished. It may take more than an hour also if your database is huge and more pictures and videos are connected to your profile.
So stay safe and Happy on your social media platform.
Tuesday, 15 November 2011
Radical Korean Spam Block: Can It Work?
If you don't use Web-based email or send your mail through an Exchange server, you're probably sending via SMTP (Simple Mail Transport Protocol). This protocol was codified almost twenty years ago, in an era when "spam" meant tinned meat, or perhaps a Monty Python sketch. Those long-ago academics had no idea that people would misuse their protocol to send advertising for erectile dysfunction drugs or false promises of Nigerian fortunes.
There's next to no security in SMTP. Malefactors can hide the source of a message by modifying sender information in the header, for example. And even if your own email uses a different system, your PC is still fully capable of sending mail using SMTP. Bot networks like the recently defeated Kelihos Botnet rely on this fact, using hordes of infected PCs to crank out spam.
As reported by the BBC, the South Korean government has proposed "Block 25", a radical plan asking Internet Service Providers to block all port 25 traffic (SMTP uses port 25). Legitimate mail would have to go through "official computer gateways."
According to Sophos's Graham Cluley, South Korea is the second biggest source of spam in the world. (The first? Why, the United States, of course!). The South Korean government's concern makes sense, but their proposed solution does not.
First, as noted in the BBC article, there are legitimate uses for port 25 that can't reasonably go through "official servers." A member of the UK's ISP association pointed out that corporate mail servers use port 25 for authenticated access. Blocking that port would prevent people working at home.
More importantly, the spammers won't be foiled for long. Perhaps they'll find a way to use another port, or subvert Web-based mail. The big business of spam and spambots won't be stopped. The only victims will be legitimate users of port 25. Yes, spam is a problem. But the real solution lies in preventing bot infestations in the first place.
How to Create Strong Passwords
We live in a password-driven world, where between four and 20 characters are the difference makers in whether you're able to access your data, communicate with friends, or make your online purchases. The problem is that passwords should be different everywhere you use them, and that can make it difficult to remember them all. And, if a password is truly strong, that makes it even more difficult. That's why we've put together this helpful password guide. Follow these tips and tricks to take total control of your terms for access.
Common Problems with Passwords
Use Different Passwords Everywhere
Remember the Underwear Meme
The saying goes like this: Passwords are like underwear. You should change them often (okay, maybe not every day). Don't share them. Don't leave them out for others to see (no sticky notes!). Oh, and they should be sexy. Wait, sorry, I mean they should be mysterious. In other words, make your password a total mystery to others.You can make your password sexy if you really want, however. I won't judge.
Avoid Common Passwords
If the word you use can be found in the dictionary, it's not a strong password. If you use numbers or letters in the order they appear on the keyboard ("1234" or "qwerty"), it's not a strong password. If it's the name of your relatives, your kids, or your pet, favorite team, or city of your birth, guess what—it's not a strong password. If it's your birthday, anniversary, date of graduation, even your car license plate number, it's not a strong password. It doesn't matter if you follow this with another number. These are all things hackers would try first. They write programs to check these kinds of passwords first, in fact.Other terms to avoid: "god," "money," "love," "monkey," "letmein," and for the love of all that's techie, if you use "password" as your password, just sign off the Internet right now.
Strong Password Solutions
How to Build Strength
To create a strong password, you should use a string of text that mixes numbers, letters that are both lowercase and uppercase, and special characters. It should be eight characters, preferably many more. A lot more. The characters should be random, and not follow from words, alphabetically, or from your keyboard layout.
So how do you make such a password?
| 1) Spell a word backwards. (Example: Turn "New York" into "kroywen.") |
| 2) Use l33t speak: Substitute numbers for certain letters. (Example: Turn "kroywen" into "kr0yw3n.") |
| 3) Randomly throw in some capital letters. (Example: Turn "kr0yw3n" into "Kr0yw3n.") |
| 4) Don't forget the special character. (Example: Turn "Kr0yw3n" into "Kr0yw3^.") |
You don't have to go for the obvious and use "0" for "o," or "@" for "a," or "3" for "e," either. As long as your replacement makes sense to you, that's all that matters. A "^" for an "n" makes sense to me.
Other tips:
Choose something simple to remember as a password, but whenever you type it, put your fingers on the wrong keys—maybe one key to the left or right. Then a password like "kroywen" becomes "jeitqwb" or "ltpuerm." This is only going to work for non-perfectionist touch-typists. And skip this tip if you type passwords on your phone; you'll only sprain a thumb trying to be inaccurate instead of letting the inaccuracy flow naturally.
Another option is to pick a pattern on the keyboard and type based on that. For example, a counter-clockwise spin around the letter d could result in "rewsxcvf." Throw in some random caps and numbers to really lock it down.
Perhaps the easiest thing to remember is an acronym from a phrase of your choice. "We didn't start the fire, it was always burning" becomes "wdstfiwab" based on the first letters of each word.
Remember, the longer the password, the stronger it is. Always. Something more than 15 characters is very difficult to remember, but it'll be a breeze with a mnemonic.
Third-Party Passwords
If you don't trust yourself to create an unbreakable password, there are plenty of tools that will make one for you. The PC Tools Secure Password Generator, for example, makes one based on your criteria: how long, include (or don't) mixed case, numbers, punctuation, similar character replacement, etc. It even provides a phonetic pronunciation guide that you use as your mantra while typing the password, for example:
| MA7ApUp# is MIKE - ALPHA - seven - ALPHA - papa - UNIFORM - papa – hash |
Password Testing
If you're worried that your password of choice isn't strong enough, check it at How Secure is My Password?. The site will even tell you how long the average PC would take to crack it. For example, cracking "kroywen" would take 13 minutes, "kr0yw3n" would take about 2 hours, "Kr0yw3^" 15 days, and "MA7ApUp#" about 3 years.
You can tell from these results that more capitals letters are better for strength and more characters (eight instead of seven) also make a huge difference. Adding a single capital letter to the end of "Kr0yw3^," such as "Kr0yw3nZ," boosts the crack time to 3 years. Throw another special character in ("Kr0yw3^Z!") and it jumps to 237 years.
Password Tracking and Changes
It's easy for me to say that you should use a strong password and then expect you to remember that messy non-word string of characters. But how dare I suggest you use a different password on every site you visit and account you own. That's madness!Or is it? Here's a simple trick that would make your already steroid-strong password even more muscular, while individualizing it for each entry. Simply take the first three letters of the site or service you're entering and append them to the beginning or end of your strong password. On Amazon, you'd have "Kr0yw3^AMA." Your e-mail could be "Kr0yw3^EMA." Facebook would be "Kr0yw3^FAC." Notice I always use all caps for the appended letters, just to crank up the security. This can work for banks, shopping, social networks, you name it. It's like creating a thousand passwords you can remember easily.
Every few months, you should change all of your passwords—everywhere. Even if you made a password that would take a few centuries to hack, you might have shared it with a co-worker or boyfriend or girlfriend, right? What happens when they become ex-coworkers or an ex-BF or ex-GF? Yeah, you can probably guess.
You could change your base ("Kr0yw3^"), which might be easy if you based it on an acronym for a longer phrase. Or you could change the appended letters by moving them to the front or even the middle ("Kr0yFACw3^" for Facebook). Perhaps switch to the last three in the service name ("OOK" for Facebook.) You could even stick in the date of the change. It's your call.
You'll be most annoyed when you encounter that select few sites that only let you have a short password of four, six, or even eight characters. What might have seemed easy before is going to soon becoming a vexing problem when you embrace the might of a strong personal password paradigm.
The Right Advice is Wrong
Some experts will tell you to do a couple of things that go against conventional password wisdom. And the reasons are simple: productivity.
For example, I read a recent treatise on why you should write down your passwords, especially if you actually go the distance and use a unique string of characters for every log in. The amount of time you could lose trying to remember each password whenever you have to type it in may not be worth it. Just try to keep the list somewhere that's not readily accessible, such as in your wallet. A desk drawer at work is not optimal for keeping out snooping co-workers.
Related advice from a Microsoft researcher says that having multiple passwords is also not worth the effort. Or, more specifically, the indirect costs of the effort of tracking them all. That's right, that big list of passwords I just said to put in your pocket? Maybe it's not worth it.
Of course, all such worries are moot if you follow the advice above and create super-seekrit-strong passwords that you can easily remember.
Tools of the Password Trade
What about password managers and other methods of entry-like biometrics? Well, of course. We'll round some of those up for you soon, but first go pick a strong password for backup, just in case.
5 Fast-Spreading Computer Viruses
Does it ever seem like everyone's out to get you? On the Internet, that is. Your every keystroke being followed, prying eyes over your shoulder when you enter in a password, fake Nigerian princes luring you with the promise of riches? You're not paranoid, you're pragmatic.
Operation Ghost Click, the largest cybercrime ring to date, was just brought down by international law enforcement efforts. Its unraveling made clear that just seven people in Russia and Estonia for a payout of $14 million could infect 4 million computers. Victims—from home users to NASA—had their browsers hijacked so that when they clicked on what they thought were legitimate web pages or ads, they instead ended up on pages that netted the criminals cash.
Spyware, phishing scams, malware, vulnerabilities, and misleading applications can all cause not just the hassle and expense of a system crash but the compromising of your most sensitive information.
So, what can you do to make sure you're protected? Make sure that you have up-to-date antispyware and antivirus running on your system with a firewall in place. Keep on top of software updates; even an outdated version of Adobe Acrobat can leave you vulnerable. Create passwords that won't make you prone to getting pwnd.
Internet threat detector Kindsight has just released a chart that tracks the movements of the top 20 perpetrators out there. Some of them are repeat offenders. Here are five of the fastest-spreading viruses that you'll want to avoid catching.
Zeus
True to its Trojan roots, Zeus (aka Zbot) comes disguised in an email. It might be as innocuous-seeming as a LinkedIn request or it could purport to warn the recipient of a problem with their financial information and offer help. No matter, the link within leads to their exposing their financial information. Once a system is infected with Zeus, passwords are collected, keystrokes are logged, and legitimate forms can be compromised with the addition of extra fields designed to nab information. Hundreds of millions of dollars have been lost to Zeus and though hundreds have been arrested, it's not likely that Zeus will stop attacking. Those looking to deploy Zeus used to have to make a significant financial donation of their own to its creator, of about $5,000. But in May, Zeus went open source, thanks to a leak.
Sality
Sality is a particularly nasty, easily spreadable virus. It wends its way into a system by executable files and then tries to download malicious files from the Internet. It can even copy itself to any removable drives, lying dormant on them until it finds its next host. Sality blocks attempts to security websites or implement security products. As with any virus, prevention is the best medicine.
Gamevance
Gamevance peddles the Designer Imposters of games. Instead of Angry Birds, it has Chick N' Bash, instead of Bejeweled, it has Diamond Jewel. But while wearing U-You instead of Calvin Klein's CK One might just leave your skin vaguely itchy, Gamevance's products can give you a full-on virus. Once a game is downloaded, so is spyware and an application that delivers pop-ups nonstop. Like any spyware, Gamvance collects users' information and tracks their online activity.
Hotbar
Clicking on a bad ActiveX file can result in installing Hotbar, as can visiting Hotbar.com and clicking on any of its games, videos, sound clips, or tools. In 2006 Zango was fined $3 million by the Federal Trade Commission for having "used unfair and deceptive methods to download adware and obstruct consumers from removing it." Hotbar spyware was thought to possibly be conquered when parent company Zango closed in 2009 after defaulting in over $44 million in loans. But Zango's assets—and Hotbar with them—no w belong to Pinball and are alive and well.
FakeSysdef
FakeSysdef seems friendly enough at first, scanning systems for hardware issues and alerting users to them. But the issues are nonexistent and downloading the fake fix module it offers is not free. FakeSysdef doesn't take no for an answer either. If a user clicks "cancel" the system will restart repeatedly until the user allows the software to be downloaded. One of the most common ways of getting infected is by performing an image search and opening a malicious results page entry that installs the malware.
Friday, 28 October 2011
Fake Netflix App Steals Passwords
Netflix has just teetered back from the brink of the Qwikster fiasco. Now there's a new problem for the service's users. The Android app for Netflix was originally released just for specific devices, though the company did recently add support for all Android 2.2 devices.
According to Symantec researchers, "A gap in availability, combined with the large interest of users attempting to get the popular service running on their Android device, created the perfect cover for Android.Fakeneflic to exploit." The fake app looks a lot like the real one, until you see them side by side.
The sole purpose of this app is to steal Netflix login credentials. The researchers noted that it asks for exactly the same permissions the real app does, even though it doesn't need most of them. When the user supposedly signs in, the app transmits the credentials to its home server. It then reports a hardware problem and advises downloading an upgrade. In truth, when you accept the alleged upgrade the app attempts to uninstall itself.
I'm not precisely clear on how the thieves will turn a profit from stealing Netflix credentials. Maybe the thieves aren't either. According to the exploit's discoverers, the server that collects those credentials is currently offline. You can view the full report, with plenty of pictures, on Symantec's Web site.
How Android Malware Makes Money
In the old, old days researchers wrote virus code to prove a point and lone coders released malware that disseminated a message or simply vandalized computers. Modern malware is all about money. Symantec has just released a report on the various techniques used to make a profit from Android-focused malware. Given that Android is now the most widespread mobile platform, it's a wide-open field for malefactors seeking to cash in.
Premium rate billing is one simple technique to skim some cash. In this case a Trojanized Android application performs some useful or entertaining function, but secretly sends SMS short codes that bill the caller  $10, $50, or even more. The attacker splits the fee with the phone service carrier. Apps can send text messages without any visible indication, making this a better choice than forced dialing of premium rate telephone numbers.
Some apps literally spy on the victim, recording phone calls and texts and tracking GPS location. It's true that on installation the victim must agree to specific permissions, but many users just routinely give an OK to all such requests.
Malicious apps that poison search engine results can drive traffic to malicious Web sites, either to encourage download of more malware or to generate income based on pay-per-view or pay-per-click advertising.
Fake antivirus, often called scareware, is a big money-maker on the PC platform, where users routinely pay $50, $60, or more for antivirus protection. Symantec hasn't yet seen a surge in Android fake antivirus, quite possibly because users would expect to pay just a few dollars for protection. Symantec's own Norton Mobile Security Lite is free, for example, as is Snuko Anti-Theft For Mobiles.
In truth, almost all of the existing monetization schemes have a low payoff. The report concludes, "While we will continue to see malicious Android applications, additional advances in the mobile technology space that allow greater monetization are likely required before malicious Android applications reach parity with Windows." You can view the entire report on Symantec's Web site.
Tuesday, 25 October 2011
Norton House of Digital Horrors
Security firm Norton recently held its House of Digital Horrors in New York City, which showcased a bevy of mobile security threats and other digital dangers.
As if today's mobile threats weren't frightening enough; the display was held in a surprisingly spine-tingling haunted house attraction. The eerie exhibit, perfect for Halloween, was complete with vampires, mummies, zombies, and other ghouls. Guests were guided though an exhibit of the most pernicious threats and dangers living in the darkest recesses of the mobile space, including data and identity theft, browser hijacking on a smartphone, and alteration of QR codes for malicious intent.
The crawl through the haunted house of mobile danger was conducted by the requisite creepy tour hosts: a one-eyed caretaker of the "Norton estate" and a dead-pan butler type, who urged tour guests to proceed through the exhibit "with caution."
Highlights included a fortune-teller who was able to gather all of your personal information not through her crystal ball but from all the personal data we put on the Internet. A black-lit room filled with macabre optical illusions clearly demonstrated that things aren’t always what they appear, and drove home the importance of having a good security solution to protect against spyware and phishing attacks. Another display featured a questionably secure jail cell containing a ravenous mobile-device thieving zombie. The lesson? You need a solution with capabilities such as remote wipe.
So without further ado, take a look inside Norton's Digital House of Horror, if you dare. For every threat and mobile monster out there, Norton proposes one of its solutions.
Good Evening!
Upon entering the Norton House of Digital Horrors, guests were greeted by some legendary figures of horror, including this guy.
Warewolf (photo courtesy Timothy Stanton)
Appallingly Bad Apps (photo courtesy Timothy Stanton)
Like a vampire offering a poisonous banquet to render unsuspecting victims helpless, the Internet offers up a host of bad apps. It's often difficult to distinguish a bad app from good. Bad apps can mislead users to download all kinds of malware including ones that steal data.
Norton Mobile Security
Symantec's answer to combating bad apps and the threats they may bring is Norton Mobile Security, which includes antivirus protection, on-demand scanning, and real-time protection against installation of malware.
Theft Tank (photo courtesy Timothy Stanton)
This member of the walking dead is being held for stealing a phone. Physical theft of smartphones and tablets is a very real threat, especially for businesses.
Norton Anti Theft
Norton's solution for physical theft of mobile devices is Norton Anti Theft, which tracks lost or stolen laptops, PCs, Android phones and tablets. It pinpoints location through the most accurate available technology, viewable in an online console. It can snap photos of a device thief using a laptop's integrated webcam.
Crystal Ball Not Needed (photo courtesy Timothy Stanton)
Does it take a fortune teller with a crystal ball to reveal your personal information? No—just a savvy evil-doer who can find out lots of information about you through the internet.
Norton Tablet Security and Norton Mobile Security
Both Norton Tablet Security and Norton Mobile Security can protect devices form outside malicious software. Norton Tablet Security features download threat protection, remote locate, remote lock, tablet threat protection, and more.
Things Aren't Always What They Appear…
In the "Gallery of Misdirection" optical illusions tricked visitors into believing they were seeing things that really weren't there. Things aren't always what they seem either when connecting mobile devices to the Internet. QR codes, barcodes embedded in advertisements, can often be used to launch malware.
Norton Snap QR Code Reader
Norton Snap QR Code Reader checks with Norton's Safe Web whenever a user scans a bar code with a mobile device. It will check to ensure that the Web site associated with the bar code is secure.
Mobile Usage Run Amok (photo courtesy Timothy Stanton)
Perhaps, scariest of all, was the display on how mobile data plan costs can spiral out of control. Norton has a solution to keep a handle on your device's plan usage.
Norton Mobile Utilities
Norton Mobile Utilities can help users keep tabs on device plan usage and battery-draining apps. It also includes some terrific real-time charts that'll help you visualize your battery and CPU usage, memory, network up and down speeds, and internal storage capacity
Subscribe to:
Posts (Atom)


































