Showing posts with label computer and data security. Show all posts
Showing posts with label computer and data security. Show all posts

Scare Tactics of Anti-Virus Company


We've all seen the messages pop up on our screen. "Malware detected!" "Your computer is infected!" "Download this software now or cybercriminals will invade your privacy, steal your identity and obliterate your soul!" These are the tactics of third-rate scams, designed to have you click on them and - ironically - install viruses and malware on your machine, but I've always wondered how somewhat "trusted" antivirus companies got away with using similar methods. A new lawsuit alleges Symantec's Norton Antivirus performs scans that don't actually scan your computer but still warn of non-existent dangers in order to get you to pay $29.99 to upgrade. Further, the plaintiff James Gross contends that even if you pay the fee, Symentec's applications don't really do anything to help your computer at all.
"The scareware does not conduct any actual diagnostic testing on the computer," reads Gross's complaint filed in Northern California. "Instead, Symantec intentionally designed its scareware to invariably report, in an extremely ominous manner, that harmful errors, privacy risks, and other computer problems exist on the user's PC, regardless of the real condition of the consumer's computer."
Gross said he bought the upgrade based on the prompt and afterwards hired IT experts to look at his machine. They told him that the scans almost always returned a negative report and that the software could not fix what it said it could. The complaint continues, "The scareware does not, and cannot, provide the benefits promised by Symantec. Accordingly, consumers are duped into purchasing software that does not function as advertised, and in fact, has very little (if any) utility."
sourse-forbes

Latest computer security threat


Latest 10 virus alerts
1 Troj/Mdrop-DKE
2 Troj/Sasfis-O
3 Troj/Keygen-FU
4 Troj/Zbot-AOY
5 Troj/Zbot-AOW
6 W32/Womble-E
7 Troj/VB-FGD
8 Troj/FakeAV-DFF
9 Troj/SWFLdr-W
10 W32/RorpiaMem-A
Top 10 viruses in October 2011
1 Troj/Invo-Zip
2 W32/Netsky
3 Mal/EncPk-EI
4 Troj/Pushdo-Gen
5 Troj/Agent-HFU
6 Mal/Iframe-E
7 Troj/Mdrop-BTV
8 Troj/Mdrop-BUF
9 Troj/Agent-HFZ
10 Troj/Agent-HGT
Top 10 virus hoaxes
1 Hotmail hoax
2 Budweiser frogs screensaver
3 Bonsai kitten
4 Olympic torch
5 MSN is closing down
6 A virtual card for you
7 Meninas da Playboy
8 Bill Gates fortune
9 JDBGMGR
10 Justice for Jamie

Enterprise resource planning(ERP) Security

                                   Introduction
Every good hacker story ends with the line: "and then he's got root access to your network and can do whatever he wants." But the story really doesn't end there. This is just the beginning of the real damage that the hacker can inflict.While most information security initiatives focus on perimeter security to keep outsiders from gaining access to the internal network, the potential for real financial loss comes from the risk of outsiders acting as authorized users to generate damaging transactions within business systems.
The continued integration of enterprise resource planning software only increases the risk of both hackers who break through perimeter security and insiders who abuse system privileges to misappropriate assets - namely cash - through acts of fraud.
Security in the e-business, integrated enterprise resource planning (ERP) world requires a new way of thinking about security - not just about the bits and bytes of network traffic, but about business transactions that inflict financial losses from systems-based fraud, abuse and errors.
The ERP market has matured to a point where heightened competition has brought declining sales. As a result, ERP vendors are committed to bundling new functionality, such as CRM and Web services-based architecture, to provide more value to their customers.
Historically, ERP security focused on the internal controls that aim to limit user behavior and privileges while organizations rely on network perimeter defenses - firewalls, VPNs, intrusion detection, etc. - to keep outsiders from accessing the ERP system. However, increasingly integrated information systems with numerous system users require new levels of transaction-level security.
And while ERP systems allow enterprises to integrate information systems with trusted partners through supply chain management, the number of authorized users continues to grow. This effectively introduces new entry points to business systems from outside the traditional IT security perimeter. Enterprises must not only trust the actions of employees but also trust partners' employees and perimeter security.
Security in an ERP World:-For most enterprises, ERP security starts with user-based controls where authorized users log in with a secure username and password. Enterprises then limit a user's system access based on their individual, customized authorization level. For example, an accounts payable clerk should not have access to human resources or inventory management modules within the ERP system
Most ERP systems offer data encryption which limits someone's ability to export the database but does not address the need to protect authorized insiders from accessing unauthorized modules in the system.
Audit logs within an ERP system track individual transactions or changes in the system but provide little detail into the relevance of the transaction. With each transaction documented individually, the audit log does not consider the context of the transaction, such as the events that occurred before or after the transaction. Internal auditors can then sample the audit logs for irregular transactions.
However, about half of all organizations do not configure their ERP system to maintain audit logs because they are concerned about performance degradation and they don't think they need it. Regrettably, these organizations believe IT security only focuses on the layers of traditional perimeter security. In a compromise between security and performance, enterprises can avoid logging every detail of system activity and focus on meaningful information that's relevant to the transaction.For organizations that do utilize audit logs, system administrators can configure customized audit reports that employ simple logic to identify "outliers" - system transactions that fall outside of normal parameters, such as date and time, location of the user logging into the system and checks larger than a predefined setting.
While it's time consuming to customize these reports, they provide hundreds of data points to manually process and are invariably riddled with false positives. Each flagged event requires manual human analysis of the event because the audit reports cannot analyze the event to determine the cause for concern.
Security Failures
When you consider that the average business loses 3 percent to 6 percent of annual revenue due to fraud, most agree that the ERP security features listed above are not working. Worse yet, businesses suffer additional losses through duplicate payment errors. The average enterprise submits duplicate payments for 2 percent of its total accounts payable. Of these duplicate payments, 10 percent are never recovered, which leads to total losses equivalent to 0.2 percent of total accounts payable.
The fact remains that applications remain highly vulnerable to external security threats. Weak passwords can be broken with simple dictionary attacks; buffer overflows can flood an application until it allows a hacker in the door. However, some of the most damaging hacks come in the form of social engineering where users are tricked into freely divulging their credentials. And of course, the real danger of external hackers comes once they enter the system as authorized users with the ability to divert payments for their benefit.
Most organizations fail in their ERP security efforts because they implement systems with a plan that leaves controls design and implementation until the end of the process. However, ERP projects are invariably over budget and behind schedule, so strict internal controls are often glossed over to keep costs down and make up time.
Some organizations decide against stringent controls because internal controls can introduce additional overhead by making it hard for employees to do their jobs with process inefficiencies.
The biggest drawback of relying on internal controls for ERP security comes from the costly and time-consuming maintenance of those controls. As employees are promoted, reassigned or terminated, organizations must continually update their business systems with each employee's correct authorization level. The advent of new business partners, the creation of new business departments or entry into new markets also requires new or modified procedural rules. Maintenance of the ERP system can turn into a never-ending resource drain.
Taken from-internet solution

 Working on orkut security, I know that fraudulent sites sometimes try to take advantage of orkut users like you and me. To help make sure that everyone is able to have a fun and safe experience on the site, I thought I'd share a few quick tips that I've picked up during my time on the orkut team. A bunch of these might seem like no-brainers, but hopefully you'll learn something new here as well:
  • Create a tough password: While "yourname123" is always a tempting password to create, keep in mind that it's just as easy for a malicious user to figure out as it is for you to remember. Try creating a password that involves a combination of letters and numbers that no one could easily guess, even if they know basic details about who you are. The same goes for your security question (the question that pops up if you forget your password)– you should try your best to pick a question that only you can answer.
  • Keep your private details private: Never share your orkut username and password with friends or on a site not authenticated by Google. orkut does not allow any external sites to store orkut login information and will never request that you enter it anywhere outside of the orkut login page. To be on the safe side, always check that your address bar reads "https://www.google.com/accounts/ServiceLogin?....." and nothing else when sharing your orkut user name and password.
  • Leave the coding to the engineers: Never copy and paste code into your address bar, no matter what it claims to be able to do. Typically these scripts actually send messages (in your name!) to your friends trying to trick them into giving up their personal information.
  • Downloads and orkut don't mix: Never download any file off of orkut, especially those that end in '.vb' or '.exe'. These files are often viruses that can infect your computer and start sending thousands of spam messages on your behalf. Sites offering special orkut themes or skins are particularly risky.
  • Think twice about external links: Links to sites outside of orkut that appear in scraps or posts have not been verified by the orkut team, and could lead you to harmful sites. We'd recommend only clicking on links that go to trusted sites or those that are from other orkut users you know well.
  • Anti-Virus software is always a good call: Even the most conscientious orkuteer can fall victim to a phishing attack, so it's important to always be alert and prepared. Regularly scanning your computer with updated anti-virus software is a great way to keep your computer secure.
  • For new orkut features, check out apps!: Sometimes an unofficial site may claim to offer special orkut features, but these sites are known for taking over orkut accounts and directly violate our Terms of Service. If you're looking for fun new orkut functionality, check out the thousands of applications that we have available. All of these apps have been built by talented developers according to standards that we believe will help to keep you safe online. If you haven't visited the app directory recently, take a look– you might be surprised at how much cool stuff you find.

via orkut blog 

Orkut Auto Scrap Virus Security


Orkut is getting targeted by a new Brazilian scrap virus, the virus infects users on clicking of the scrap message claiming to show some kind of video but it contain some exe file wich will be install  in your system on click.So Please dont Click simply delete this scrap.If you have clicked by mistake please follow following steps and uninstall this exe
This virus that claimes to be a video is a .exe file which infects users computer and sends the same scrap to all your friends on Orkut, the virus installs "orkutkut exe" and "imglog exe" on the infected computer, the virus can easily be disabled by following the steps below:
1.Kill both("orkutkut exe" and "imglog exe") the process from the 2.task manager (CTRL+SHIFT+ESC).
3.Remove startup entries using msconfig exe
4.Delete the two above mentioned files from system32 folder.
To secure yourself from such threats never click on unknown links in your scrapbook.!!!!HAPPY ORKUTING

How to Get Rid of a Computer Virus

Computer viruses come in many forms and can cause various kinds of damage to your system. Fortunately, most viruses are easily dealt with and effective methods for eliminating them are often developed as soon as the viruses are discovered. If you think your computer may be infected, take any necessary steps to clear your system and avoid infecting other computers.
Instructions
1.Visit your virus-scan software manufacturer's Web site and install any virus updates that are available. Then run the software. The software may not be able to delete the virus, but it may be able to identify it.
2.Search the Web for information regarding your specific virus by typing the name of the virus or its associated file into a search engine followed by the word "virus." For example, "Melissa virus," "BubbleBoy virus," etc.
3.Download and install any patches or other programs that will help you eliminate the virus. Or follow any instructions you find on deleting the virus manually.
4.Run another virus scan to make sure the virus has been dealt with properly.
Tips & Warnings
If you think your computer was affected with an e-mail virus that mails itself to people in your e-mail address book, contact those people and tell them not to open the messages or attachments.


-Web based email usually has built in virus scanning so viruses never reach your machine.


-Generally, deleting the file that caused the virus isn't sufficient to eliminate the problem, since many viruses can create new files or corrupt existing files. Your best bet is to use anti-virus software or specific online instructions.


-Avoid sending out any e-mails until you have properly eliminated the virus. Many viruses can attach themselves to outgoing messages without your knowledge, causing you to unwittingly infect the computers of your friends and colleagues



How to remove a computer virus and spyware.

Symptoms that may be the result of ordinary Windows functions
A computer virus infection may cause the following problems:

    * Windows does not start even though you have not made any system changes or even though you have not installed or removed any programs.
    * Windows does not start because certain important system files are missing. Additionally, you receive an error message that lists the missing files.
    * The computer sometimes starts as expected. However, at other times, the computer stops responding before the desktop icons and the taskbar appear.
    * The computer runs very slowly. Additionally, the computer takes longer than expected to start.
    * You receive out-of-memory error messages even though the computer has sufficient RAM.
    * New programs are installed incorrectly.
    * Windows spontaneously restarts unexpectedly.
    * Programs that used to run stop responding frequently. Even if you remove and reinstall the programs, the issue continues to occur.
    * A disk utility such as Scandisk reports multiple serious disk errors.
    * A partition disappears.
    * The computer always stops responding when you try to use Microsoft Office products.
    * You cannot start Windows Task Manager.
    * Antivirus software indicates that a computer virus is present.

Symptoms of a computer virus

If you suspect or confirm that your computer is infected with a computer virus, obtain the current antivirus software. The following are some primary indicators that a computer may be infected:

    * The computer runs slower than usual.
    * The computer stops responding, or it locks up frequently.
    * The computer crashes, and then it restarts every few minutes.
    * The computer restarts on its own. Additionally, the computer does not run as usual.
    * Applications on the computer do not work correctly.
    * Disks or disk drives are inaccessible.
    * You cannot print items correctly.
    * You see unusual error messages.
    * You see distorted menus and dialog boxes.
    * There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension.
    * An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted.
    * An antivirus program cannot be installed on the computer, or the antivirus program will not run.
    * New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs.
    * Strange sounds or music plays from the speakers unexpectedly.
    * A program disappears from the computer even though you did not intentionally remove the program.

Note These are common signs of infection. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus. Unless you run the Microsoft Malicious Software Removal Tool, and then you install industry-standard, up-to-date antivirus software on your computer, you cannot be certain whether a computer is infected with a computer virus or not.

Symptoms of worms and trojan horse viruses in e-mail messages
When a computer virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:

    * The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.
    * A copy of the infected file may be sent to all the addresses in an e-mail address list.
    * The computer virus may reformat the hard disk. This behavior will delete files and programs.
    * The computer virus may install hidden programs, such as pirated software. This pirated software may then be distributed and sold from the computer.
    * The computer virus may reduce security. This could enable intruders to remotely access the computer or the network.
    * You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs.
    * Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.

What is Spyware?
Spyware can install on your computer without your knowledge. These programs can change your computer’s configuration or collect advertising data and personal information. Spyware can track internet searching habits and possibly redirect web site activity. 

Symptoms of Spyware
When a computer becomes affected by Spyware, the following may result:

    * Slow internet connection.
    * Changing your web browser’s home page.
    * Loss of internet connectivity.
    * Failure to open some programs, including security software.
    * Unable to visit specific websites, which may include redirecting you to another one.
How to remove a computer virus and spyware.
Even for an expert, removing a computer virus or spyware can be a difficult task without the help of computer malicious software removal tools. Some computer viruses and other unwanted softwarereinstall themselves after the viruses and spyware have been detected and removed. Fortunately, by updating the computer and by using malicious software removal tools, you can help permanently remove unwanted software.

To remove a computer virus and other malicious software, follow these steps:

Install the latest updates from Microsoft Update:

   1. For Windows Vista and Windows 7:
         1. Click the Pearl (Start) button, then type Windows Update in the search box.
         2. In the results area, click Windows Update.
         3. Click Check for Updates.
         4. Follow the instructions to download and install the latest Windows Updates.
   2. For Windows XP:
         1. Click Start, then click Run.
         2. Click the Automatic Updates tab and hoose the Automatic (recommended) option.
         3. Click OK.

Cyber Security

As we know we are leaving in cyber world where technology and internet provide lot of benefits with huge dangers aspect.cyber world serves equally to both hackers and crackers.
It also provide lot of way of security hence we need to take precautions to protect(secure) yourself online.


 What are some warnings to remember or some security tips to use?

    Don't trust candy from strangers - Finding something on the internet does not guarantee that it is true.or secure or it will full fill all security criteria 

Anyone can publish information online without checking it is secure(security) or not , so before accepting a statement as fact or taking action, verify that the source is reliable.or secure 
It is also easy for attackers to "spoof" email addresses, so verify that an email is legitimate before opening an unexpected email attachment or responding to a request for personal information 
If it sounds too good to be true, it probably is - You have probably seen many emails promising fantastic rewards or monetary gifts. However, regardless of what the email claims, there are not any wealthy strangers desperate to send you money. Beware of grand promises—they are most likely spam, hoaxes, or phishing schemes . Also be wary of pop-up windows and advertisements for free downloadable software—they may be disguising spyware.    
Don't advertise that you are away from home - Some email accounts, especially within an organization, offer a feature (called an autoresponder)
that allows you to create an "away" message if you are going to be away from your email for an extended period of time. The message is automatically
sent to anyone who emails you while the autoresponder is enabled. While this is a helpful feature for letting your contacts know that you will not be
able to respond right away, be careful how you phrase your message. You do not want to let potential attackers know that you are not home, or, worse, give specific details about your location and itinerary. Safer options include phrases such as "I will not have access to email between [date] and [date].
" If possible, also restrict the recipients of the message to people within your organization or in your address book. If your away message replies to spam, it only confirms that your email account is active. This may increase the amount of spam you receive  Lock up your valuables - If an attacker is able to access or breaches your cesurity, your personal data, he or she may be able to compromise or steal the information.
Take steps to secure this information by following good security practices
 Some of the most basic precautions or security include locking your computer when you step away; using firewalls, anti-virus software, and strong passwords security ; installing appropriate software security updates; and taking precautions or security when browsing or using email.
 Have a backup plan - Since your information could be lost or compromised (due to an equipment malfunction, an error, or an attack),
 make regular backups of your information so that you still have clean, complete copies
Backups also help you identify what has been changed or lost.

Computer Hackers and Predators


How computer hackers and predators are threat for your computer security?

People with bad mind, not the computers, create computer threats. Computer predators victimize unaware people for their gain.  A predator having access to the Internet is exponentially bigger threat to your PC than the others. Computer hackers and predators are unauthorized users who break into others computer systems to steal, change or destroy valuable information, often by installing dangerous and harmful malware without your knowledge. The use of clever tactics and detailed technical knowledge help them to access the information you really don’t want to let them know.
What computer hackers and predators do to find you?
Everyone who uses a computer with a Internet connection is susceptible by the threats of computer hackers and predators. These online demons mainly use spam emails or instant messages, phishing scams, and bogus Web sites (fake or duplicate webpage which almost look like the original) to deliver dangerous and harmful malware to the computer and disable your computer security. They will also try to access your computer and thus your private information directly if you had not taken protection by configuring your firewall. They can also peruse your personal Web page or monitor your chat room conversations. Generally by using a fake identity, predators can fool you and make you into revealing sensitive personal and financial information.
Be aware: computer hackers and predators can do the following things to you.
With the help of malware transmitted by the hacker, he can get your personal as well as financial information without your knowledge. Then he can use this information for his benefit and it will harm you in the aspect of loss of money as well as private information and data. In either case, they may:
•    Know your usernames and passwords and will change it or use it according to him.
•    Using your info they can open credit card and bank accounts in your name
•    Steal your money and Ruin your credit
•    additional credit cards  or Request new account Personal Identification Numbers (PINs) o
•    Make purchases form offline stores.
•    Add themselves or an alias that they control as an authorized user so it’s easier to use your credit
•    Obtain cash advances from your credit card
•     Abuse your Social Security number
•    Sell your information to such person who will use it for illegal purposes
Especially predators can pose a serious physical threat. Be extremely cautious when agreeing to meet an online “friend” or acquaintance in person.
Ways to know that are you in the net or not?
Regularly check the accuracy of your personal accounts, credit cards bills and other documents. Are there any unexplained transactions?
Questionable or unauthorized changes?
 If so, the dangerous and harmful malware is already installed by predators or hackers in your computer.
What can I do about computer hackers and predators?
Read as much as possible about the articles on computer security threats on this blog and increase our knowledge about this. Although Hackers and predators pose equally serious and but very different threats you will wiser enough to avoid their tricks.
To protect your computer from hackers and predators:
•    Regularly check the accuracy of your personal accounts and deal with any discrepancies instantly.
•    Use extreme caution when entering any chat rooms or posting on personal Web pages
•    Put a limit on the personal information you post on a personal Web pages
•    Carefully monitor requests  on social networking sites by online “friends” or acquaintances for predatory behavior
•    Keep personal and financial information out of any type of online conversations
Take these steps to protect your computer from hackers right away:
•    Switch to 2 way firewall.
•    Update your operating system on regular basis.
•    Increase your browser security settings.
•    Only download software from trusted sites you trust.
•    First carefully evaluate free software then use and do same in the case of file-sharing applications before downloading them.
•    Practice safe email protocol.
•    Don't respond messages from unknown senders, even don’t open it.
•    Immediately delete messages you suspect to be spam.
•    Make sure that you have the best internet security products installed on your computer.
•    Always use antivirus protection
•    Also Get antispyware software protection
An unprotected computer is a like a free gift for computer hackers and predators. To protect your computer from hackers and predators also use a spam filter or gateway to scan inbound email or IM messages. While free anti-spyware and antivirus downloads are widely available, they just can’t keep up with the continuous onslaught of new malware strains due to their limited functionality. Previously undetected forms of malware can often do the most damage, so it’s necessary to have up-to-the-minute updated and guaranteed protection.

How to Avoid Phishing Scams

The number and sophistication of phishing scams sent out to consumers is continuing to increase dramatically. While online banking and e-commerce is very safe, as a general rule you should be careful about giving out your personal financial information over the Internet. The Anti-Phishing Working Group has compiled a list of recommendations below that you can use to avoid becoming a victim of these scams.

* Be suspicious of any email with urgent requests for personal financial information
o unless the email is digitally signed, you can't be sure it wasn't forged or 'spoofed'
o phishers typically include upsetting or exciting (but false) statements in their emails to get people to react immediately
o they typically ask for information such as usernames, passwords, credit card numbers, social security numbers, date of birth, etc.
o phisher emails are typically NOT personalized, but they can be. Valid messages from your bank or e-commerce company generally are personalized, but always call to check if you are unsure
* Don't use the links in an email, instant message, or chat to get to any web page if you suspect the message might not be authentic or you don't know the sender or user's handle
o instead, call the company on the telephone, or log onto the website directly by typing in the Web adress in your browser
* Avoid filling out forms in email messages that ask for personal financial information
o you should only communicate information such as credit card numbers or account information via a secure website or the telephone
* Always ensure that you're using a secure website when submitting credit card or other sensitive information via your Web browser
o Phishers are now able to 'spoof,' or forge BOTH the "https://" that you normally see when you're on a secure Web server AND a legitimate-looking address. You may even see both in the link of a scam email. Again, make it a habit to enter the address of any banking, shopping, auction, or financial transaction website yourself and not depend on displayed links.
o Phishers may also forge the yellow lock you would normally see near the bottom of your screen on a secure site. The lock has usually been considered as another indicator that you are on a 'safe' site. The lock, when double-clicked, displays the security certificate for the site. If you get any warnings displayed that the address of the site you have displayed does NOT match the certificate, do not continue.
* Remember not all scam sites will try to show the "https://" and/or the security lock. Get in the habit of looking at the address line, too. Were you directed to PayPal? Does the address line display something different like "http://www.gotyouscammed.com/paypal/login.htm?" Be aware of where you are going.
* Consider installing a Web browser tool bar to help protect you from known fraudulent websites. These toolbars match where you are going with lists of known phisher Web sites and will alert you.
o The newer version of Internet Explorer version 7 includes this tool bar as does FireFox version 2
o EarthLink ScamBlocker is part of a browser toolbar that is free to all Internet users - download at http://www.earthlink.net/earthlinktoolbar
* Regularly log into your online accounts
o don't leave it for as long as a month before you check each account
* Regularly check your bank, credit and debit card satements to ensure that all transactions are legitimate
o if anything is suspicious or you don't recognize the transaction, contact your bank and all card issuers
* Ensure that your browser is up to date and security patches applied
* Always report "phishing" or “spoofed” e-mails to the following groups:
o use the form on this page or forward the email to reportphishing@antiphishing.org
o forward the email to the Federal Trade Commission at spam@uce.gov
o forward the email to the "abuse" email address at the company that is being spoofed (e.g. "spoof@ebay.com")
o when forwarding spoofed messages, always include the entire original email with its original header information intact
o notify The Internet Crime Complaint Center of the FBI by filing a complaint on their website: www.ic3.gov/

Denial of Service attack (DoS)


A denial-of-service (DoS) attack prevents users from accessing a computer or website.
In a DoS attack, a hacker attempts to overload or shut down a computer, so that
legitimate users can no longer access it. Typical DoS attacks target web servers
and aim to make websites unavailable. No data is stolen or compromised, but the
interruption to the service can be costly for a company.
The most common type of DoS attack involves sending more traffic to a computer than
it can handle. Rudimentary methods include sending outsized data packets or sending
email attachments with names that are longer than permitted by the mail programs.
[sintuhack]
An attack can also exploit the way that a “session” of communications is established
when a user first contacts the computer. If the hacker sends many requests for a
connection rapidly and then fails to respond to the reply, the bogus requests are left in
a buffer for a while. Genuine users’ requests cannot be processed, so that they can’t
contact the computer.
[sintuhack]
Another method is to send an “IP ping” message (message requiring a response from
other computers) that appears to come from the victim’s computer. The message goes
out to a large number of computers, which all try to respond. The victim is flooded with
replies and the computer can no longer handle genuine traffic.
[sintuhack]
A distributed denial-of-service (DDoS) attack uses numerous computers to launch the attack. Typically, hackers use a virus or Trojan to open a “back door” on other people’s
computers and take control of them. These “zombie” computers can be used to launch
a coordinated denial-of-service attack.
[sintuhack]

HOW to Track and Recover Your Lost/Stolen iPhone

iPhone is the world’s best smart phone available today without any doubt. People carry their phones everywhere they go, and hence there is always a chance of them forgetting their iPhone somewhere or the iPhone getting stolen. Learn how to track, message, erase and recover your lost or stolen iPhone.

1. Track your iPhone via MobileMe
Apple has announced a new service called Find My iPhone that will allow iPhone owners to remotely locate their lost or stolen iPhones using the iPhone’s GPS. The service will be available as part of Apple’s MobileMe online subscription service.

Find My iPhone will pinpoint the iPhone’s current location using Google Maps and let owners send and display a message on the iPhone even if it’s locked, presumably to provide information on how to return the phone to the finder of the phone.
2. iPhone anti-theft solution – iLocalis
iLocalis has the following uses-

    * Never lose you iPhone: If it is missing just log onto the iLocalis site and you’ll know where it was located last.
    * Retrieve a stolen iPhone: If your iPhone is stolen you can log into the site and check out where it’s at. Extra features built into iLocalis allow you to send text messages or make calls on your iPhone when you don’t even have it with you. If you iPhone is stolen log in and send yourself a text message. If the thief changed the sim card you’ll have their phone number!
    * Allow your family and friends to know where you are: iLocalis will send a message to your friends when you are near by. You can also set it up to allow your friends to locate you. If your friend also has iLocalis you can send messages to each other for free. No txt messaging charges.
    * iLocalis can also be used for a business that needs location services for their employees. Employees carrying iPhones with iLocalis can be tracked via the web site easily.

uAndroid's Security Framework


                            uAndroid's Security Framework
The Google Android mobile phone platform is one of the most anticipated smartphone operating systems. Android defines a new component-based framework for developing mobile applications, where each application is comprised of different numbers and types of components. Activity components form the basis of the user interface; each screen presented to the user is a different Activity. Service components provide background processing that continues even after its application loses focus. Services also define arbitrary interfaces for communicating with other applications. Content Provider components share information in relational database form. For instance, the system includes an application with a Content Provider devoted to sharing the user's address book upon which other applications can query. Finally, Broadcast Receiver components act as an asynchronous mailbox for messages from the system and other applications. As a whole, this application framework supports a flexible degree of collaboration between applications, where dependencies can be as simple or complex as a situation requires.

Internet Security

                        Tips for browsing internet safely
The concern for internet safety is a global phenomenon, mostly for those who are new-fangled to internet. While the prevalence of social networking websites, online communities and internet-enabled processes should be great news for individual, corporate and government users, the concern for safety remains a major source of concern. The 21st century is the age of computers and World Wide Web. Everyone starting from child to old is accustomed with web browsing. But the question arises how much we are safe on the internet? Hackers and malicious software is a great threat to our individual online privacy. So we need to protect our self from these dangerous aspects of internet. Following are some steps that can ensure a safe browsing practice. 
 1–Use Common Sense 
 To browse the internet safely, it’s best if you do so by using common sense. Do not click on advertisements that may harm your computer, and stay away from sites that promise “free” items, cash or other services simply by entering your personal information. Just because a website looks official, this does not mean that it can’t harm your computer.
2 – Use a Firewall 

 To improve the safety of your internet browsing, it’s highly recommended that you install some high-quality firewall software. Having a firewall can help prevent programs from infiltrating your computer, and may also protect against some hackers or internet criminals.
3- Use Strong Passwords

 Ensure data security by using strong passwords for your online accounts and your system files. Do not use your name or birth date as a password since they are easy to crack. Instead, use a password that contains alphanumeric characters and is at least eight characters long. Also, do not store passwords on your system. If remembering all your passwords is difficult, use a password manager program to organize and manage your passwords.
 4- Install Antivirus and Antispyware Tools 

 Use an antivirus and an antispyware tool to keep your system protected from malicious programs, such as viruses, worms, adware, and spyware. Configure these tools to perform regular full system scans on your computer.
5 – Be Aware 

When other people are using your computer, it’s best if you supervise their activities. Even if a friend asks to check their email, its best if you have them login under a other account that you have created for others to use. Having a Guest account on your computer enables you to allow others to use your computer without having to worry about them installing potentially malicious software. When creating a Guest account, disable sharing of important files on your computer. In addition to this, you should always make sure that any sensitive files are password-protected. Don’t load non-essential programs off the Internet, especially things like toolbars, screensavers, or video programs. These programs normally install extra, malicious software that causes problems and often requires a repair to remove effectively. Don’t click on anything in a pop-up and unsolicited links received in email, instant messages, or chat rooms, as it might install malware.
6- Do Not Open Attachments from Unsolicited Emails
Attachments that come with unwanted emails can contain malicious programs, such as viruses and worms. These malicious programs often cause severe damage to your system. Therefore, it is best that you straight away delete any unwanted emails you receive. You must also scan the attachments that you obtain from known sources before opening them.
7- Lock icon in the browser doesn’t means it’s secure

When the lock icon appears in the browser, many of us believe we are opening a secure site. This is because the lock icon indicates there is an SSL encrypted connection between the browser and the server to protect the personal sensitive information. However, it does not present any security from malware. In fact, it’s the reverse because most Web security products are totally blind to encrypted connections: it’s the perfect vehicle for malware to penetrate a machine. There have been many cases where hackers emulate bank, credit card sites complete with spoofed SSL certificates that are difficult for a user to identify as deceptive. So keep away from the unknown site which shows lock icon.
8- Keep your Operating System, Software, and Drivers Up-To-Date
     

Mobile security:Tips for using Bluetooth Securely

All  deficiencies(described in previuos post )  leave a Bluetooth device vulnerable to security threats. Even though security gaps are being filled every day by the manufacturer and technologist, Following are some of the tips that a normal user can keep in mind and protect himself from an amateur BlueTooth  security breacher.[sintuhack]
  • Keep BlueTooth   in the disabled state, enable it only when needed and disable immediately after the intended task is completed.[sintuhack]
  • Keep the device in non-discoverable (hidden) mode,[sintuhack]
  • DO NOT accept any unknown and unexpected request for pairing your device.[sintuhack]

  • Use non regular patterns as PIN keys while pairing a device. Use those key combinations which are non sequential, non obvious on the keypad.[sintuhack]
  • Keep a check of all paired devices in the past from time to time and delete any paired device which you are not sure about.[sintuhack]
  • Register your device at the Manufacturer site and insure that security updates are installed regularly to protect from previously know threat which had been rectified in new models.[sintuhack]
  • Always enable encryption when establishing Bluetooth connection to your PC.[sintuhack]
Above Bluetooth Security Tips should make your Bluetooth experience trouble free. Good Luck…!!! And that’s the end of chapter on bluetooth.[sintuhack].

Bluetooth Security Risks:MOBILE SECURITY



Bluetooth Security Risks
1. The first step in using any Bluetooth device is to turn on the Bluetooth feature in it. The default state of Bluetooth in any device is “Off” mode. 
2. Once Bluetooth is turned on, it is in active but dormant state. In order to use it, it needs to be put in to “Discoverable” state. In theory when a device is in “non discoverable” state it should not be visible to other devices but in reality the device is still discoverable to those devices it has made a connection before using MAC address. A hacker seeing the Blue LED can use Brute Force address discovery process to record the MAC address and hack the device using software such as RedFang.


3. During communication process also Bluetooth technology exposes itself to security breach as the address itself is not encrypted although the message may be encrypted. Technique such as frequency hogging provides some protection but is not completely secure.
4. There are devices available in the market which can capture a Bluetooth signal from the air and analyze. At present cost is prohibitive for casual hackers to acquire some of these devices but still a professional hacker can use those devices and hack vital information.
5. Many owners leave the Bluetooth device in the discoverable mode after actual use due to ignorance or simply forget to turn off “discoverable” mode which gives hackers easy opportunity to pair with their device and hack.
6. Pairing two Bluetooth devices usually does not require any authentication, however using a service like file transfer or data/video/voice exchange require some authentication by entering PIN. Once PINs are entered a link key is generated and stored in the device’s memory. This process is not required for next time onwards.
7. Many vendors do not implement authentication and authorization process correctly allowing hackers to steal information or use one’s phone or use it for making calls or SMS.

BLuebugging:Can Breach YOUR Mobile Security



BLuebugging was somewhat like bluesnarfing but the difference is that it is more harmful to your mobile from the prospective of security of your mobile. It was first invented in 2004 by German scientist. In the initial phase, it was necessary to pair devices via Bluetooth before the security breacher  try to breach your mobile with the bugger, but now a days its not needed to pair up the devices.[sintuhack]. It can also possible to break you mobile security via the Bluetooth enabled headset which is used to take call as per to free your hands.[sintuhack]

At early stage it was done with laptop but now a days such powerful PDA and mobile phones are available  in the market that it can be done without laptops .[sintuhack]. you may be happy that your mobile Bluetooth has only a small range so its not easy to pair up your device hence you mobile is secured. But did you know that in market antenna’s are available which can send and receive weak signal s and hence data can be transferred from range of even 200 meters.[sintuhack]

Bluesnarfing:Mobile Security Breach

Bluesnarfing refers to a the method in which one has gained access to data, which is stored on a Bluetooth enabled phone of other people.
Literally Bluesnarfing can be described as unauthorized access of information from a wireless device through a Bluetooth connection. The level of access depends from case to case, but, in general, it involves pretty much anything that's stored on the user's mobile device.
Bluesnarfing allows the using person to make phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations, and connect to the Internet. he can also download the material in his mobile from the victim mobile.
The good news is, bluesnarfing requires advanced equipment and much advanace expertise


In this field. As bluejacking can be done at the range of 10 meters, in bluesnarfing the intruder must be present within a 30 ft. range.
If the phone is in non-discoverable mode, then its not true that you cant be a victim of this.
Its adds only some problem and makes it little bit more difficult for intruders to bluesnarf your phone.


It can be possible from phone and laptop both to bluesnarf a mobile. By just using some bluesnarfing tools (Bluesnarfer, Blooover)

on mobile phone or laptop, anyone can detect and access those vulnerable mobile phones to view and download entire phonebook, calendar, real time clock, business card and other important private data without alerting the phone owner(you).




There's little info on whether Bluesnarfing is possible without the targeted phone being paired with the computer running the aforementioned software application, but anyone cannot completely rule out this possibility, either.


So that’s all about bluesnarfing. Wait till next post to know about other mobile security breach methods………….

How do I protect my PC from spyware?

A firewall is considered to be the most popular tool to protect a computer from spyware. Firewalls are integrated into operating systems (OS) and permanently examine incoming and outgoing addresses to computer network ports. They analyze data packages coming to Internet ports and mail ports according to the type of request and the addressee. Most firewalls allow or deny some types of addresses, but this is a weak point because spyware may be integrated inside many packages or disguised as a Web browser. This type of spyware cannot be detected by a firewall, and gets inside the PC to start its malicious activity. Also, firewalls are usually resource-consuming, so the price for relative security is your PC running much slower.

The problem of firewall relative protection is successfully solved by proactive security systems. Such systems analyze all application activity on the PC for its potential maliciousness, according to predefined rules of malicious or non-dangerous behavior. In case of a real threat, proactive systems block dangerous programs before any damage to the OS is done.

An anti-spyware solutions called Safe’n’Sec+Anti-Spyware, is a special solution consisting of Safe’n’Sec behavior analyzer -- which blocks previously unknown spyware (new modifications) -- and the Anti-Spyware module, which detects already known spyware with the help of extended anti-spyware signature databases. This Anti-Spyware module has the option to delete malware from the user's PC. The solution is absolutely compatible with any traditional security software installed on your computer. Anti-Spyware solutions efficiently protect your confidential data from unauthorized access, whether you work in the system or just browse the Internet.

How to Be Safer on Twitter

“Twitter is insecure. Twitter is the root of all evil.”

Right. Much has indeed been written about Twitter’s security – or lack thereof– in just the past couple of months. In taking in what others have to say, though, I can’t help but think it’s being unfairly attacked.

Let’s take a fair and objective view of some of the issues, and see what, if anything, a user can do to reduce her risk.

Twitter, the wildly popular micro-blogging web site, has roared onto the scene in an amazingly short time, even by Internet standards. Twitter users can post short (140-character) messages known as “tweets” to all their followers. Pretty much anyone can follow anyone else’s tweets on Twitter, although there are some minimal privacy settings and such for those who want to limit the scope of where their tweets go and who can see them.

It’s through this simple matrix of followers and writers that communities of like-minded people have joined one another in reading and posting their tweets.

But several articles and blog entries have been published declaring Twitter to be insecure. A common theme among the naysayers has been Twitter’s use of TinyURL, a site/service that encodes long URLs—we’ve all seen them—to be just a few characters long. No doubt this is used so that people can post tweets with URLs and still fit within the 140-character tweet limit.

The problem with TinyURL and similar encoding mechanisms is that the end user really doesn’t know what’s in the original URL itself. Thus, a tweet could be pointing the reader to a hostile site containing maliciously formed data that could quite conceivably attack the reader’s browser.

All of this is true, of course, but so what? The truth is that any URL we click on or enter into our browsers manually can take us to sites that contain malicious data. Granted, some sites are going to seem more trustworthy than others: a respected news outlet is likely to be more trustworthy than (say) www.click-here-to-infect-your-computer.com—which, by the way, I think is not a registered domain.

Even still, I again ask the question: so what? There is an inherent risk in pointing your browser to any web site. We’ve discussed here numerous ways of shoring up your browser so that you’re less likely to have your system compromised, even if you visit a site containing malicious data. All of these things are entirely relevant in the context of Twitter, of course.

Another common complaint is that there’s no verification of a Twitter user’s identity, so someone could trivially pose as (say) a celebrity and the public would be none the wiser. This too is quite true, but it’s nothing new with Twitter.

Anyone still remember the old “kremvax” April Fools’ joke from 1984? Spoofing an identity was as true then as it is now. In the absence of a trustworthy cryptographic signature, digital identity must not be trusted.

Now, to be fair, there have been a few published coding vulnerabilities on Twitter, including some cross-site scripting problems, “clickjacking” problems, etc. But from what I can tell as an outsider (and a Twitter user), the folks at Twitter have fixed these problems on the server as they’ve been reported. I don’t have data on how rapidly they’ve been fixed, but they do appear to be addressing them.

All of these security and privacy concerns are valid, but they’re by no means new or unique to Twitter. No, it seems to me that Twitter is being unfairly attacked for whatever reasons. I’ve heard many folks complain about Twitter’s 140-character tweet limit, saying that nothing of value can be communicated in such a small message, therefore Twitter must be without merit.

I won’t get into a debate of whether one can say something valuable on 140 characters or not, but suffice to say that I’ve seen many 140-character tweets that were of value to me. But let’s get past that and consider some positive recommendations on how to safely use twitter, assuming that you also want to hear what some of your colleagues want to say in 140 characters.

  1. • Don’t click on encoded URLs if you at all doubt them. If they point to something you feel you do want to read, direct message or email the tweet’s author and ask for the full citation, and then decide whether it deserves your trust.
  2. • Harden your browser anyway, just like I’ve suggested here many times.
  3. • Follow people who post things you’re genuinely interested in. Follow people you trust. Verify their Twitter identities via a trustworthy channel like, for instance, an encrypted or cryptographically signed email.
  4. • Avoid twits. There is a lot of noise on twitter. Life is too short for that blather. Shut it off.
  5. • If you’re concerned about the privacy of what you post, set your own account to “protect my posts,” which restricts your tweets to only your followers. Approve (or disapprove) your followers. Block followers you don’t know or otherwise don’t want reading your tweets.
  6. • Avoid posting URLs, or post really short URLs so that your tweets don’t automatically invoke TinyURL. If you want to point to a URL, tell your followers to direct message you to request the full URL.

These, of course, are just some basic precautions you could take if you wanted to use Twitter in a reasonably safe way. Above all, though, treat it for what it is—a means of posting short bursts of information to people. If you want your own tweets to be valuable to others, be concise. Very concise