Showing posts with label viruses. Show all posts
Showing posts with label viruses. Show all posts

Tools to Track & Recover Your Stolen Laptop



Off late, in coffee shops, college campuses, hotel lobbies and even in cars, laptops and notebook computers are being targeted by criminals. And these incidents are increasing at an alarming rate.[sintuhack].As per FBI, 97% of the stolen laptops are never recovered. That is a staggering stat. But don’t worry, we can increase the odds of recovering / tracking your stolen laptop and that too for FREE![sintuhack]

Ways to Track and Recover your Stolen Laptop

1. Track your Stolen laptop with Adeona

Adeona from University of Washington provides an open source, [sintuhack].free and completely non-proprietary way to track your stolen laptop. [sintuhack].You can install Adeona on your laptop and go as there’s no need to rely on a single third party! What’s more, Adeona addresses a critical privacy goal different from existing commercial offerings. It is privacy-preserving. This means that no one besides the owner (or an agent of the owner’s choosing) can use Adeona to track a laptop. Unlike other systems, users of Adeona can be rest assured that no one can abuse the system in order to track where they use their laptop. You can read the detailed article on Adeona here
.[sintuhack].
2. Locate your laptop with LocateMyLaptop.com
LocateMyLaptop is a free service that offers a stealthy app on your laptop which reports its position whenever the computer is connected to the Internet.[sintuhack]. If it’s lost or stolen, you can issue a self-destruct command to erase all the data on the hard drive – but that requires upgrading to the Platinum Plan, which costs $3/month. But you do not need to pay anything until the disaster strikes. this is because, tracking of laptop is FREE, and you can upgrade to the platinum service only if your laptop gets stolen.

3. Browser Plugin to Track your stolen Laptop – Loki[sintuhack].

Loki is basically a service which can add location of users to any website.[sintuhack]. But it can be tweaked in such a way that you can log directly into Loki to see your laptop’s location on a map, or enable “sharing” – which blasts your location to a public Web page, to Twitter, Facebook, or a handful of other services.[sintuhack]. Only concern is, Loki is not always reliable as it sometimes fails to update the public page with laptop’s location.[sintuhack]. This issue is seen even when Loki browser plugin on the laptop knew where it is.[sintuhack]. Hopefully this issue should be fixed by the next release.[sintuhack]

4. Locate your stolen Laptop with LocatePC

LocatePC is FREE software which lets you track and finally get back your stolen computer or laptop back to you.[sintuhack]. LocatePC sends you a secret email message from your stolen computer or laptop with some crucial information. But again, we will be hoping that the thief will connect the laptop to the internet before formatting. Still, something is better than nothing right?[sintuhack]

computer security

Computer security is the process of preventing and detecting unauthorized use of your computer. Prevention measures help you to stop unauthorized users (also known as "intruders") from accessing any part of your computer system. Detection helps you to determine whether or not someone attempted to break into your system, if they were successful, and what they may have done.

We use computers for everything from banking and investing to shopping and communicating with others through email or chat programs. Although you may not consider your communications "top secret," you probably do not want strangers reading your email, using your computer to attack other systems, sending forged email from your computer, or examining personal information stored on your computer (such as financial statements).
   Intruders (also referred to as hackers, attackers, or crackers) may not care about your identity. Often they want to gain control of your computer so they can use it to launch attacks on other computer systems.

Having control of your computer gives them the ability to hide their true location as they launch attacks, often against high-profile computer systems such as government or financial systems. Even if you have a computer connected to the Internet only to play the latest games or to send email to friends and family, your computer may be a target.

Intruders may be able to watch all your actions on the computer, or cause damage to your computer by reformatting your hard drive or changing your data.

Unfortunately, intruders are always discovering new vulnerabilities (informally called "holes") to exploit in computer software. The complexity of software makes it increasingly difficult to thoroughly test the security of computer systems.

Also, some software applications have default settings that allow other users to access your computer unless you change the settings to be more secure. Examples include chat programs that let outsiders execute commands on your computer or web browsers that could allow someone to place harmful programs on your computer that run when you click on them.

Remove virus – Trojan Horse Sheur2

The Trojan Horse Sheur2 is a dangerous and harmful Trojan that infects Windows 98, Windows 95, Windows XP, Windows ME, Windows Vista, Windows 2000 computers. If your computer constantly raises speaker beep sounds, shows “Blue Screen” and reports that the error is produced by missing dll’s, registry keys, and Windows files, or your pop-up blocker is unable to block the pornographic and gambling related bulk popups then you are sure to have Trojan Horse Sheur2 on your computer.

The Trojan Horse Sheur2 is not just one computer infection. It comes in various forms and related infections. Some related infections are: SHeur2.hsf, SHeur2.FO, SHeur2, SHeur2.AS, SHeur2.MR, SHeur2.ISU, SHeur2.BBJ, sheur2.hsd, and SHeur2.CFT

SHeur enters your computer through backdoor without your knowledge. It usually gets into your computer due to browser security holes on your computer or if you visit questionable websites such as gambling, pornography, and hacking related websites.
Once installed on your computer, it hides itself on your computer as a legal software and the will start performing its various annoyances.

It drops malicious code to your local or network computer, disables the firewall and antivirus software configured on your computer, redirects your web browser to malicious websites, downloads malicious code, slowdowns the performance of your computer considerably, slowdowns Internet connection, and forwards passwords, login names and other confidential private information from your computer to remote computers.
How To Remove Trojan Horse Sheur2

You can remove SHeur2 Trojan using and automatic removal tool or manually. To remove it manually, you need to:

1.    Restart you computer Safe Mode.
2.    Open Internet Explorer and clean browser history and temporary internet files.
3.    Remove startup items.
4.    Remove Registry entries related to SHeur2
5.    Reboot your computer.


If the Trojan is still there you can try performing a System Restore to remove it. It is very difficult to remove SHeur2 manually because it re-installs itself if you have not completely removed its presence from your computer. Also it requires an expertise to handle system registry else you may end up in damaging your computer even more than it is damaged by this Trojan. It is therefore strongly recommended to use an automatic trojan Sheur removal tool to get rid of this virus from your computer

Document Viruses


Document or “macro” viruses take advantage of macros – commands that are embedded in fi les and run automatically.
Many applications, such as word processing and spreadsheet programs, use macros.
A macro virus is a macro program that can copy itself and spread from one file to
another. If you open a file that contains a macro virus, the virus copies itself into the
application’s startup files. The computer is now infected.
When you next open a file using the same application, the virus infects that file. If your
computer is on a network, the infection can spread rapidly: when you send an infected
file to someone else, they can become infected too. A malicious macro can also make
changes to your documents or settings.
Macro viruses infect files used in most offices and some can infect several file types,
such as Word and Excel files. They can also spread to any platform on which their host
application runs.
Macro viruses first appeared in the mid-1990s and rapidly became the most serious
virus threat of that time. Few viruses of this type are seen now

LATEST VIRUS NAME..

    1.     Virus Name:     Virus:W32/Sality
   A malicious program that secretly integrates itself into program or datafiles.It spreads by integrating itself into more files each time the host program is run.
              
    2.     Virus Name:           Trojan-Downloader:W32/Hiloti
                   This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.
              
    3.     Virus Name:  Trojan-Downloader:W32/Fakerean.gen!A
This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.
              
    4.     Virus Name:  Trojan-Downloader:W32/Wimad.gen!A
     A trojan that secretly downloads malicious files from a remote server, then installs and executes the files.
              
    5.     Virus Name:           Trojan-Downloader:W32/Oficla
This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.
              
    6.     Virus Name:           Trojan:AndroidOS/Tapsnake
 Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate.
              
    7.     Virus Name:           Email-Worm:W32/Bagle.GE
  This type of worm is embedded in an e-mail attachment, and spreads using the infected computer's e-mailing networks.
              
    8.     Virus Name:           Virus:W32/Bursted
A malicious program that secretly integrates itself into program or data files. It spreads by integrating itself into  more files each time the host program is run.
              
    9.     Virus Name:           Trojan:W32/Qhost
Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate.
              
    10.     Virus Name:           Trojan:W32/Agent.DKJC
Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate.  

Email Security...some Basic point

In today’s electronic world, email is critical to any business being competitive. In most cases it now forms the backbone of most organisations’ day-to-day activities, and its use will continue to grow. According to the The Radicati Group’s study, “Microsoft Exchange and Outlook Analysis, 2005-2009,” the worldwide email market will grow from 1.2 billion mailboxes in 2005 to 1.8 billion mailboxes in 2009.[sintuhack]
As email becomes more prevalent in the market, the importance of email security becomes more significant. In particular, the security implications associated with the management of email storage, policy enforcement, auditing, archiving and data recovery. Managing large, active stores of information takes time and effort in order to avoid failures – failures that will impact the users and therefore the business, undoubtedly leading to lost productivity. For secure and effective storage management, organisations must take a proactive approach and invest wisely in a comprehensive solution.When considering a secure email storage management solution, a layered approach, combining both business processes and applications makes sense. By considering the service email provides to the business, email management can be broken down into a number of components: mail flow, storage, and user access – both at the server and user levels. Whilst each one of these components should be addressed separately, they must be viewed as part of a total security agenda.[sintuhack]
Mail flow can encompass many aspects of an email system. However, the security of mail flow is for the large part focused around the auditing and tracking of mails into and out of the organisation. Monitoring the content and ensuring that any email that has been sent and received complies with business policy is fundamental.
[sintuhack].Proving who has sent or received email is a lawful requirement for many industries and email can often be used as evidence in fraud and human resource court cases.[sintuhack],Another key aspect of the management of mail flow security is the protection of the business from malicious or unlawful attacks. It is at the gateway into the mail system where a business must protect itself via a variety of methods including hardware and software protection systems, such as spam filters and virus scanner[sintuhack].

Common mobile viruses:Mobile Security Threat



How they spread and what are the effects:

Cabir: When this virus infects  your mobile then  message 'Caribe' will be displayed  at each  time you switch off and  on the mobile. These worms are generally  spread through blue tooth signals from surroundings  mobiles. 
Duts: A parasitic  file infector virus .its alos  known as Pocket PC. It try to infect all EXE files which are more than 4kb present in the directory where it saved. 
Skulls:  it is a Trojan horse. Means a piece of code will be  downloaded  on your mobile nad then the virus called Skull replaces your phone desktop into  image of skull as icon.it is very dangerous as  It is usually  transferred with all phone applications and also with SMS and MMS. 
Comm warrior: It's also spread through MMS  and  unsecured blue tooth  to other devices. It has more impact on devices running under OS Symbian Series 60. This virus launches The executable worm file and the worm  hunt for gaining access to your blue tooth devices and sends the infected files under various different  name to various random device.

The 25 Most Common Mistakes in Email Security

25 tips to bring newbie Internet users up to speed so they stop comprimising your network security.
I still remember receiving my first phishing email in my AOL account. I had won the AOL lottery! As good as it sounded, I was skeptical at best. So without much thought, I opened the email and clicked on the link inside to check if I truly was a millionaire after all. Almost instantly, my computer crashed, and with each subsequent restart would crash again.
Countless computer crashes and thousands of spam emails later, I had learned the lesson that just opening spam email can bring harm to my computer. Unfortunately there are a whole host of traps and errors that catch new email users just because "they didn't know any better".
In this article we focus on 25 of the most common and easy to fix mistakes that people make when it comes to email security. We've designed this article with the new internet user in mind, so if you're an email expert, you may want to pass this along to your novice friends.
HERE I AM GOING TO EXPLAIN SOME POINT WHERE COMMON USER IS USEDT TO TRAPPED BY HACKERS/PHISHERS------
  1. Properly managing your email accounts
  2. Emailing the right people
  3. Making backups and keeping records
  4. Avoiding fraudulent email
  5. Avoiding malware
  6. Keeping hackers at bay
Properly managing your email accounts

1. Using just one email account.

Individuals new to email often think about their email account like they do their home address, you only have one home address, so you should only have one email. Instead, you should think about your email address like you do your keys; while it may be OK to use the same key for your front and your back door, having a single key open everything is both impractical and unsafe.

A good rule of thumb for the average email user is to keep a minimum of three email accounts. Your work account should be used exclusively for work-related conversations. Your second email account should be used for personal conversations and contacts, and your third email account should be used as a general catch-all for all hazardous behavior. That means that you should always sign up for newsletters and contests only through your third email account. Similarly, if you have to post your email account online, such as for your personal blog, you should only use your third email account (and post a web friendly form of it at that).

While your first and second email accounts can be paid or freebie, your third 'catch-all' account should always be a freebie account such as those offered by Gmail or Yahoo!. You should plan on having to dump and change out this account every six months, as the catch-all account will eventually become spammed when a newsletter manager decides to sell your name or a spammer steals your email address off a Web site.

2. Holding onto spammed-out accounts too long.

It is simply a fact of life that email accounts will accumulate spam over time. This is especially true of the account you use to sign up for newsletters and that you post online (which as stated above should not be your main email account). When this happens, it is best to simply dump the email account and start afresh. Unfortunately, however, many new email users get very attached to their email accounts and instead just wade through dozens of pieces of spam every day. To avoid the problem, prepare yourself mentally ahead of time for the idea that you will have to dump your 'catch all' account every six months.

3. Not closing the browser after logging out.

When you are checking your email at a library or cybercafé you not only need to log out of your email when you are done, but you also need to make sure to close the browser window completely. Some email services display your username (but not your password) even after you have logged out. While the service does this for your convenience, it compromises your email security.

4. Forgetting to delete browser cache, history and passwords.

After using a public terminal, it is important that you remember to delete the browser cache, history, and passwords. Most browsers automatically keep track of all the web pages that you have visited, and some keep track of any passwords and personal information that you enter in order to help you fill out similar forms in the future.

If this information falls into the wrong hands, it can lead to identity theft and stolen bank and email information. Because the stakes are so high, it is important that new internet users be aware of how to clear a public computers browser cache so that they can delete private information before lurking hackers can get a hold of it.

For those of you using Mozilla's Firefox, simply press Ctrl+Shift+Del. Opera users need go to Tools>>Delete Private Data. And users of Microsoft's Internet Explorer need to go to Tools>>Internet Options then click the 'Clear History', 'Delete Cookies', and 'Delete Files' buttons.



5. Using unsecure email accounts to send and receive sensitive corporate information.

Large corporations invest huge amounts of money to ensure that their computer networks and email remain secure. Despite their efforts, careless employees using personal email accounts to conduct company business and pass along sensitive data can undermine the security measures in place. So make sure that you don't risk your company's security, and your job, by transmitting sensitive company data via your own personal computer or email address.

6. Forgetting the telephone option

One of the most important lessons about email security is that no matter how many steps you take to secure your email, it will never be foolproof. This is never truer than when using a public computer. So unless you need a written record of something or are communicating across the globe, consider whether a simple phone call rather than an email is a better option. While a phone conversation may require a few extra minutes, when compared with accessing email through a public computer, a phone call is a far more secure option and it does not leave a paper trail.

Emailing the right people

7. Not using the Blind Carbon Copy (BCC) option.

When you put a person's email addresses in the BCC: rather than the CC: window, none of the recipients can see the addresses of the other email recipients.

New email users often rely too much on the TO: because it is the default way of sending emails. That is fine as long as you are writing to just one person or a few family members. But if you are sending mail out to a diverse group of people, confusing BCC: and CC: raises some serious privacy and security concerns. It takes just one spammer to get a hold of the email and immediately everyone on your email list gets spammed.

Even if the honesty of the group isn't in question, many email programs are setup to automatically add to the address books any incoming email addresses. That means that some people in the group will inadvertently have added the entire list to their address book, and as a result, if one of their computers is infected with "Zombie" malware and silently sends out spam emails, you will have just caused the entire list to get spammed.

8. Being trigger happy with the "Reply All" button.

Sometimes the mistake isn't in deciding between CC: and BCC: but between hitting Reply All instead of Reply. When you hit Reply All, your email message is sent to everyone included on the original email, and if you didn't intend to include them, the information can be disastrous from both a security and personal humiliation perspective:

Example 1: "A very successful salesman at our networking company had a large email address book filled with his best customers, including some very important and conservative government contacts. With a single click, he accidentally sent a file chock-full of his favorite pornographic cartoons and jokes to everyone on his special customer list. His subject line: 'Special deals for my best customers!' Needless to say, he's cutting deals for another company these days."

Example 2: "A woman was in torment over a busted romance. She wrote a lengthy, detailed message to a girlfriend, adding that her ex-boyfriend preferred men to women. But instead of hitting Reply to a previous message from her girlfriend, she hit Reply All. Her secret was sent to dozens of people she didn't even know (including me), plus the aforementioned ex and his new boyfriend. As if that weren't bad enough, she did this two more times in quick succession!

9. Spamming as a result of forwarding email.

Forwarding emails can be a great way to quickly bring someone up to speed on a subject without having to write up a summary email, but if you aren't careful, forwarding emails can create a significant security threat for yourself and the earlier recipients of the email. As an email is forwarded, the recipients of the mail (until that point in time) are automatically listed in the body of the email. As the chain keeps moving forward, more and more recipient ids are placed on the list.

Unfortunately, if a spammer or someone just looking to make a quick buck gets a hold of the email, they can then sell the entire list of email ids and then everyone will start to get spammed. It only takes a few seconds to delete all the previous recipient ids before forwarding a piece of mail, and it can avoid the terrible situation of you being the cause of all your friends or coworkers getting spammed.

Making backups and keeping records

10. Failing to back up emails.

Emails are not just for idle chatting, but can also be used to make legally binding contracts, major financial decisions, and conduct professional meetings. Just as you would keep a hard copy of other important business and personal documents, it is important that you regularly back up your email to preserve a record if your email client crashes and loses data (It happened to Gmail as recently as December 2006).

Thankfully, most email providers make it rather simple to back up your email by allowing you to export emails to a particular folder and then just creating a copy of the folder and storing it onto a writeable CD, DVD, removable disk, or any other type of media. If that simple exporting process sounds too complicated, you can just buy automated backup software that will take care of the whole thing for you. Whether you purchase the software or decide to back up manually, it is important that you make and follow a regular backup schedule, as this is the sort of thing that new email users tend to just put off. The frequency of backups necessary for you will of course depend on your email usage, but under no circumstances should it be done less frequently than every 3 months.

11. Mobile access: Presuming a backup exists.

Mobile email access, such as through BlackBerry, has revolutionized the way we think about email; no longer is it tied to a PC, but rather it can be checked on-the-go anywhere. Most new BlackBerry users simply assume that a copy of the emails they check and delete off the BlackBerry will still be available on their home or office computer.

It is important to keep in mind, however, that some email servers and client software download emails to the Blackberry device and then delete them from the server. Thus, for some mobile email access devices, if you delete it from the device, you have deleted it from your Inbox.

Just be aware of the default settings of your email client and make sure that if you want a copy of the email retained, you have adjusted the email client's settings to make it happen. And preferably make sure of this before you decide to delete that important email.

12. Thinking that an erased email is gone forever.

We've all sent an embarrassing or unfortunate email and sighed relief when it was finally deleted, thinking the whole episode was behind us. Think again. Just because you delete an email message from your inbox and the sender deletes it from their 'Sent' inbox, does not mean that the email is lost forever. In fact, messages that are deleted often still exist in backup folders on remote servers for years, and can be retrieved by skilled professionals.

So start to think of what you write in an email as a permanent document. Be careful about what you put into writing, because it can come back to haunt you many years after you assumed it was gone forever.

Avoiding fraudulent email

13. Believing you won the lottery … and other scam titles.

Spammers use a wide variety of clever titles to get you to open emails which they fill with all sorts of bad things. New email users often make the mistake of opening these emails. So in an effort to bring you up to speed, let me tell you quickly:

* You have not won the Irish Lotto, the Yahoo Lottery, or any other big cash prize.
* There is no actual Nigerian King or Prince trying to send you $10 million.
* Your Bank Account Details do not need to be reconfirmed immediately.
* You do not have an unclaimed inheritance.
* You never actually sent that "Returned Mail".
* The News Headline email is not just someone informing you about the daily news.
* You have not won an iPod Nano.

14. Not recognizing phishing attacks in email content.

While never opening a phishing email is the best way to secure your computer, even the most experienced email user will occasionally accidentally open up a phishing email. At this point, the key to limiting your damage is recognizing the phishing email for what it is.

Phishing is a type of online fraud wherein the sender of the email tries to trick you into giving out personal passwords or banking information. The sender will typically steal the logo from a well-known bank or PayPal and try to format the email to look like it comes from the bank. Usually the phishing email asks for you to click on a link in order to confirm your banking information or password, but it may just ask you to reply to the email with your personal information.

Whatever form the phishing attempt takes, the goal is to fool you into entering your information into something which appears to be safe and secure, but in fact is just a dummy site set up by the scammer. If you provide the phisher with personal information, he will use that information to try to steal your identity and your money.

Signs of phishing include:

* A logo that looks distorted or stretched.
* Email that refers to you as "Dear Customer" or "Dear User" rather than including your actual name.
* Email that warns you that an account of yours will be shut down unless you reconfirm your billing information immediately.
* An email threatening legal action.
* Email which comes from an account similar, but different from, the one the company usually uses.
* An email that claims 'Security Compromises' or 'Security Threats' and requires immediate action.

If you suspect that an email is a phishing attempt, the best defense is to never open the email in the first place. But assuming you have already opened it, do not reply or click on the link in the email. If you want to verify the message, manually type in the URL of the company into your browser instead of clicking on the embedded link.

15. Sending personal and financial information via email.

Banks and online stores provide, almost without exception, a secured section on their website where you can input your personal and financial information. They do this precisely because email, no matter how well protected, is more easily hacked than well secured sites. Consequently, you should avoid writing to your bank via email and consider any online store that requests that you send them private information via email suspect.

This same rule of avoiding placing financial information in emails to online businesses also holds true for personal emails. If, for example, you need to give your credit card information to your college student child, it is far more secure to do so over the phone than via email.

16. Unsubscribing to newsletters you never subscribed to.

A common technique used by spammers is to send out thousands of fake newsletters from organizations with an "unsubscribe" link on the bottom of the newsletter. Email users who then enter their email into the supposed "unsubscribe" list are then sent loads of spam. So if you don't specifically remember subscribing to the newsletter, you are better off just blacklisting the email address, rather than following the link and possibly picking up a Trojan horse or unknowingly signing yourself up for yet more spam.

Avoiding malware

17. Trusting your friends email.

Most new internet users are very careful when it comes to emails from senders they don't recognize. But when a friend sends an email, all caution goes out the window as they just assume it is safe because they know that the sender wouldn't intend to hurt them. The truth is, an email from a friend's ID is just as likely to contain a virus or malware as a stranger's. The reason is that most malware is circulated by people who have no idea they are sending it, because hackers are using their computer as a zombie.

It is important to maintain and keep updated email scanning and Anti-virus software, and to use it to scan ALL incoming emails.

18. Deleting spam instead of blacklisting it.

An email blacklist is a user created list of email accounts that are labeled as spammers. When you 'blacklist' an email sender, you tell your email client to stop trusting emails from this particular sender and to start assuming that they are spam.

Unfortunately, new internet users are often timid to use the blacklist feature on their email client, and instead just delete spam emails. While not every piece of spam is from repeat senders, a surprising amount of it is. So by training yourself to hit the blacklist button instead of the delete button when confronted with spam, you can, in the course of a few months, drastically limit the amount of spam that reaches your Inbox.

19. Disabling the email spam filter.

New email users typically do not start out with a lot of spam in their email account and thus do not value the help that an email spam filter can provide at the beginning of their email usage. Because no spam filter is perfect, initially the hassle of having to look through one's spam box looking for wrongly blocked emails leads many new email users to instead just disable their email spam filter altogether.

However, as an email account gets older it tends to pick up more spam, and without the spam filter an email account can quickly become unwieldy. So instead of disabling their filter early on, new internet users should take the time to whitelist emails from friends that get caught up in the spam filter. Then, when the levels of spam start to pick up, the email account will remain useful and fewer and fewer friends will get caught up in the filter.
20. Failing to scan all email attachments.

Nine out of every ten viruses that infect a computer reach it through an email attachment. Yet despite this ratio, many people still do not scan all incoming email attachments. Maybe it is our experience with snail mail, but often when we see an email with an attachment from someone we know, we just assume that the mail and its attachment are safe. Of course that assumption is wrong, as most email viruses are sent by 'Zombies' which have infected a computer and caused it to send out viruses without the owner even knowing.

What makes this oversight even more scandalous is the fact that a number of free email clients provide an email attachment scanner built-in. For example, if you use Gmail or Yahoo! for your email, every email and attachment you send or receive is automatically scanned. So if you do not want to invest in a third-party scanner and your email provider does not provide attachment scanning built-in, you should access your attachments through an email provider that offers free virus scanning by first forwarding your attachments to that account before opening them.

Keeping hackers at bay

21. Sharing your account information with others.

We've all done it – we need an urgent mail checked, and we call up our spouse or friend and request them to check our email on our behalf. Of course, we trust these people, but once the password is known to anybody other than you, your account is no longer as secure as it was.

The real problem is that your friend might not use the same security measures that you do. Your friend might be accessing his email through an unsecured wireless account, he may not keep his anti-virus software up to date, or he might be infected with a keylogger virus that automatically steals your password once he enters it. So ensure that you are the only person that knows your personal access information, and if you write it down, make sure to do so in a way that outsiders won't be able to understand easily what they are looking at if they happen to find your records.

22. Using simple and easy-to-guess passwords.

Hackers use computer programs that scroll through common names to compile possible user names, and then send spam emails to those usernames. When you open that spam email, a little hidden piece of code in the email sends a message back to the hacker letting him know that the account is valid, at which point they turn to the task of trying to guess your password.

Hackers often create programs which cycle through common English words and number combinations in order to try to guess a password. As a consequence, passwords that consist of a single word, a name, or a date are frequently "guessed" by hackers. So when creating a password use uncommon number and letter combinations which do not form a word found in a dictionary. A strong password should have a minimum of eight characters, be as meaningless as possible, as well as use both upper and lowercase letters. Creating a tough password means that the hacker's computer program will have to scroll through tens of thousands of options before guessing your password, and in that time most hackers simply give up.

23. Failing to encrypt your important emails.

No matter how many steps you take to minimize the chance that your email is being monitored by hackers, you should always assume that someone else is watching whatever comes in and out of your computer. Given this assumption, it is important to encrypt your emails to make sure that if someone is monitoring your account, at least they can't understand what you're saying.

While there are some top-of-the-line email encryption services for those with a big budget, if you are new to email and just want a simple and cheap but effective solution, you can follow these step-by-step 20 minute instructions to install PGP, the most common email encryption standard. Encrypting all your email may be unrealistic, but some mail is too sensitive to send in the clear, and for those emails, PGP is an important email security step.
24. Not encrypting your wireless connection.

While encrypting your important emails makes it hard for hackers who have access to your email to understand what they say, it is even better to keep hackers from getting access to your emails in the first place.
One of the most vulnerable points in an emails trip from you to the email recipient is the point between your laptop and the wireless router that you use to connect to the internet. Consequently, it is important that you encrypt your wifi network with the WPA2 encryption standard. The upgrade process is relatively simple and straightforward, even for the newest internet user, and the fifteen minutes it takes are well worth the step up in email security.


25. Failing to use digital signatures.

The law now recognizes email as an important form of communication for major undertakings such as signing a contract or entering into a financial agreement. While the ability to enter into these contracts online has made all of our lives easier, it has also created the added concern of someone forging your emails and entering into agreements on your behalf without your consent.

One way to combat email forgery is to use a digital signature whenever you sign an important email. A digital signature will help prove who and from what computer an email comes from, and that the email has not been altered in transit. By establishing the habit of using an email signature whenever you sign important emails, you will not only make it harder for the other party to those agreements to try to modify the email when they want to get out of it, but it will also give you extra credibility when someone tries to claim that you have agreed to a contract via email that you never did.

How do I protect my PC from spyware?

A firewall is considered to be the most popular tool to protect a computer from spyware. Firewalls are integrated into operating systems (OS) and permanently examine incoming and outgoing addresses to computer network ports. They analyze data packages coming to Internet ports and mail ports according to the type of request and the addressee. Most firewalls allow or deny some types of addresses, but this is a weak point because spyware may be integrated inside many packages or disguised as a Web browser. This type of spyware cannot be detected by a firewall, and gets inside the PC to start its malicious activity. Also, firewalls are usually resource-consuming, so the price for relative security is your PC running much slower.

The problem of firewall relative protection is successfully solved by proactive security systems. Such systems analyze all application activity on the PC for its potential maliciousness, according to predefined rules of malicious or non-dangerous behavior. In case of a real threat, proactive systems block dangerous programs before any damage to the OS is done.

An anti-spyware solutions called Safe’n’Sec+Anti-Spyware, is a special solution consisting of Safe’n’Sec behavior analyzer -- which blocks previously unknown spyware (new modifications) -- and the Anti-Spyware module, which detects already known spyware with the help of extended anti-spyware signature databases. This Anti-Spyware module has the option to delete malware from the user's PC. The solution is absolutely compatible with any traditional security software installed on your computer. Anti-Spyware solutions efficiently protect your confidential data from unauthorized access, whether you work in the system or just browse the Internet.

World of Warcraft Attacked by Phishers

World of Warcraft players desperate for a new mount to traverse the online role-playing game's fantasy world are getting a reality check from hackers who have devised a clever pop-up phishing scam to spread malware.

Security technicians at F-Secure Security Lab on Tuesday posted a blog entry Tuesday detailing the latest scam making its way through the world's most popular massively multiplayer online role-playing game (MMORPG).

With more than 11.5 million monthly subscribers, Blizzard Entertainment's World of Warcraft is not only the most successful MMORPG in history, but also a very popular environment for hackers, phishers and assorted click-fraud scam artists.

This latest hoax preys on players' desire to add mounts for their online avatars to ride. After clicking on a link to get a new trial mount, players are redirected to a malicious phishing Web site that mimics an official WoW page.

Those players who are still hard up for a mount are then prompted to enter their WoW log-in details.

"Apart from losing all the gold and items saved, a compromised account could also be used to send out the malicious messages to other victims, adding insult to injury," the researchers warned in their blog post. "An interesting detail about this particular site is that a reverse-IP check on its IP address turned up over a dozen other WoW phishing sites."

F-Secure officials remind players that phishing sites like the one identified today are blocked by the security firm's browser protection software.

World of Warcraft holds an estimated 62 percent of the MMORPG market. The third expansion set, Cataclysm, was announced at the BlizzCon conference earlier this year.

14 More Open Source Tools to Protect Your Identity

AS IN PREVIOUS POST I DID EXPLAIN 14 OPEN TOOL FOR SECURE YOUR DATA,IN THIS POST I ADD SOME MORE TOOL AND EXPLAIN TO--SO READ AND APLY THEN GIVE COMENT...AS ADVICE....YOUR ADVICE WILL PROVIDE ME A WAY AND ENERGY TO COLLECT MORE INFORMATION ABOUT YOUR NEED
To help you keep from making the same sort of mistake I did, we've compiled a list of 14 more open source apps that can help protect your identity. Some of these fit into traditional security categories, like anti-spam, anti-virus, and firewalls. Others, like browsers, e-mail, and PDF tools, we've included in this list because they include encryption or other security features that can help you protect yourself.
No one is likely to need all 14 of these apps, but the list should give you plenty of options for filling in any security gaps in your system.Open Source Anti-Spam=========

Open Source Compression

1. 7-zip

7-zip offers higher than normal compression ratios and supports multiple file formats. However, in order to take advantage of its strong AES-256 encryption capabilities, you'll need to create either 7z or zip files. Operating System: Windows, Linux, OS X.

2. PeaZip

One of the most flexible compression utilities available, PeaZip currently supports about 90 different archive file formats. It also supports multiple encryption standards and even offers a two-factor authentication option for maximum security. Operating System: Windows, Linux, OS X.

3. KGB Archiver

One big benefit of using this compression utility is that it encrypts files with AES-256 encryption automatically. It also supports multiple file formats and nine different languages (but not Russian, which seems odd for an app named after the KGB). Operating System: Windows.

Open Source Data Destruction

4. Darik's Boot And Nuke

Also known as "DBAN," Darik's Boot and Nuke allows you to create a boot disk (CD, DVD, thumb drive, or even an old floppy) which will completely erase all the drives it can detect on your system. It's a great tool if you're getting rid of an old computer, but not as helpful if you're just deleting a few files. Operating System: OS Independent.

5. Eraser

If you need to erase only a few files—perhaps your financial or tax records, work files, or as the website suggests, bad poetry—Eraser is the tool for you. It overwrites deleted data multiple times, making it nearly impossible to retrieve the "erased" files. Operating System: Windows.

6. BleachBit

Like Eraser, BleachBit can completely erase files, but it also includes a number of other features to help protect your privacy and speed up your system. For example, it can erase your cache, remove your browsing history and cookies, clean up junk left by more than 50 applications, and much more. Operating System: Windows, Linux.

Open Source Email

7. Thunderbird

This e-mail client from Mozilla (the makers of Firefox) includes built-in encryption capabilities, anti-spam, and phishing protection. It further protects you by blocking remote images in e-mail and alerting you when security updates become available. Operating System, Windows, Linux, OS X.

8. Zmail

Need to send a secret e-mail? Zmail lets you send e-mail messages anonymously if you know your SMTP server address. Operating System: OS Independent.

Open Source Encryption

9. AxCrypt

With more than 1.5 million registered users, AxCrypt has become one of the most popular open-source encryption applications. It integrates seamlessly with Windows—simply right-click a file to encrypt it. Operating System: Windows.

10. TrueCrypt

With more than 12 million downloads, TrueCrypt is also a very popular way to protect your files. While AxCrypt focuses on encrypting individual files, TrueCrypt makes it easy to encrypt a drive partition or an entire drive (including USB thumb drives). Operating System: Windows, Linux, OS X.

11. Gnu Privacy Guard

Also known as "GPG," Gnu Privacy Guard lets you encrypt and digitally sign documents before transmitting them. This is a command line tool, but the Web site includes links to a number of graphical interfaces for the software. Operating System: Windows, Linux, Unix, OS X.

Open Source File Transfer

12. FileZilla

FileZilla supports regular FTP and the more secure FTPS and SFTP protocols. While the client version should work with any operating system, the server version only works with Windows machines. Operating System: Windows, Linux, OS X.

13. WinSCP

This Windows-only file transfer tool has won tons of awards and supports FTP, SFTP, and the older SCP file transfer protocols. Note that it's a client-only tool—i.e., you can use it to download files from other sites, but you can't use it to set up your own FTP server. Operating System: Windows.

Open Source File Sharing

14. Waste

While most file sharing networks are designed to help users circumvent copyright laws, Waste at least claims to be aimed at law-abiding citizens. With it, small groups (10-50 nodes) can chat and share data securely without opening their systems to unauthorized users. Operating System: Windows, Linux, OS X.

Open Source Firewalls

15. Firestarter

Unlike most of the open-source firewalls, Firestarter can protect a single PC as well as a network. Best of all, you can probably install it and be up and running in just a couple of minutes. Operating System: Linux.

16. IPCop

IPCop is a complete Linux distribution designed to be used as a standalone firewall and boasts a very user-friendly interface. To use it, you'll need an old PC to connect to your network. Operating System: Linux.

17. Vyatta

Vyatta sells open source networking hardware and software commerically atwww.vyatta.com, and they also maintain the free, community version. With the community version, you can turn a PC into a network appliance that offers routing, firewalling, VPN, intrusion prevention, and WAN load balancing services. Operating System: Linux.
32. SmoothWall E
Because it's designed to be used by people with no knowledge of Linux, SmoothWall Express is an excellent option if you aren't a technical whiz, but want to tackle setting up your own network. A supported commercial version is also available. Operating System: Linux.
33. LEA
The "Linux Embedded Appliance Framework" (aka LEAF) can be used as an Internet gateway, router, firewall, or wireless access point. This app requires a little more know-how than some of the other choices in the category, but is a good option. Operating System: Linux.

14:-Open Source Tools to Protect Your Identity

Usually these lists of open source software start with statistics or general observations on current trends in the open source community. This one starts with a personal story.
I used to use a thumb drive to backup my budget software, and I also kept a copy of our tax returns on the same drive. While the files were password protected, I didn't encrypt them because the drive never left the house, and we don't exactly live in a high crime area.
Then one day my friend was looking for a drive to carry some files to the school where he teaches. As you probably guessed, he grabbed the drive with our financial info on it. And as you probably also guessed, someone stole his computer and the thumb drive right out of his classroom. As a result, I've had the great joy of spending many, many hours changing our account numbers, checking our credit reports, and setting up fraud alerts.
To help you keep from making the same sort of mistake I did, we've compiled a list of 14 open source apps that can help protect your identity. Some of these fit into traditional security categories, like anti-spam, anti-virus, and firewalls. Others, like browsers, e-mail, and PDF tools, we've included in this list because they include encryption or other security features that can help you protect yourself.
No one is likely to need all 14 of these apps, but the list should give you plenty of options for filling in any security gaps in your system.Open Source Anti-Spam
1. SpamAssassin
The highly acclaimed "#1 open-source spam filter," SpamAssassin, uses a number of different features to identify spam, including header tests, body phrase tests, Bayesian filtering, blacklists and whitelists, and others. It can be used on its own, but it's also been incorporated into a number of other commercial and open-source applications. Operating System: OS Independent.
2. ASSP
Humbly claiming to be "the absolute best SPAM fighting weapon that the world has ever known," ASSP is short for "Anti-Spam SMTP Proxy" Server. While it takes a little work to get it up and running at first, it doesn't require a lot of maintenance, and the site wiki includes extensive help on configuring the app so that it works for you. Operating System: Windows, Linux, OS X.
3. Spamato
Available as an Outlook add-on, as a Thunderbird extension, or as a stand-alone proxy, Spamato uses multiple filters to separate junk mail from the stuff you actually want to receive. Unlike some anti-spam tools, it also lets you see why a message gets classified as spam and adjust your settings as necessary. Operating System: Windows, Linux, OS X.
Open Source Anti-Spyware
4. Nixory
Nixory will quickly scan your system and remove any malicious cookies from Firefox. Unlike some similar apps, you can use it alongside other anti-virus or anti-spyware applications without first disabling those systems. Operating System: Windows, Linux, OS X.
Open Source Anti-Virus/Anti-Malware
5. ClamAV
One of the best-known open-source security projects, ClamAV provides e-mail virus and malware scanning for Unix-based systems. Its owners update its prodigious virus database several times each day to provide up-to-the minute protection from evolving threats. Operating System: Linux.
6. ClamWin
Based on the well-respected ClamAV engine, ClamWin integrates with Microsoft Outlook and Windows Explorer to scan files for viruses and other malware. You can set it up to automatically download the updated virus database, and you can schedule system scans. However, unlike many commercial products, it does not include a real-time scanner for files you receive by e-mail. You'll need to save files and right-click in order to scan them for viruses. Operating System: Windows.
7. ClamTK
As you might expect, this is another interface for ClamAV, this time for Linux only. Operating System: Linux.
8. Moon Secure
This app also uses the Clam AV engine (though developers claim to be working on one of their own), but offers a different interface and some different features. Operating System: Windows.
Open Source Backup
9. Amanda
Currently protecting more than 500,000 computers, Amanda is one of the most popular (if not the most popular) open-source backup and recovery program. Importantly, it encrypts backup data both in transit and at rest. Several commercial vendors (notably, Zmanda) use Amanda to offer cloud backup services for users who prefer to store archived data off-site. Operating System: Windows, Linux, OS X.
10. Areca Backup
Designed to be both flexible and simple, Areca Backup makes it extremely easy to archive your files and work with those archived files (browse, merge, track versions, etc.). It also gives users the option to encrypt backup files with strong algorithms. Operating System: Windows, Linux.
11. Bacula
While it's primarily aimed at enterprises and users with large networks, Bacula can also be used to backup a small home network or a single system. It's an excellent program (one of the most popular open source enterprise apps), but you need to be pretty tech-savvy to use it. Operating System: Windows, Linux, OS X.
Open Source Browser
12. Firefox
An independent study cited on the Firefox site claims that Internet Explorer users are vulnerable to threats 98 percent of the time while Firefox users are only vulnerable 2 percent of the time. In addition to being secure, Firefox is fast and highly customizable. Operating System: Windows, Linux, OS X.
13. Tor Browser Bundle
If you're really paranoid about privacy or have other reasons for wanting to browse the Internet anonymously, the Tor Bundle will install with your existing browser for ultimate protection. When its running, no one can tell what sites you are visiting, sites can't figure out your physical location, and you should be able to access sites that are blocked by governments or Web filtering software. You can also install it on a thumb drive for mobility. Operating System: Windows.
14. TorK
For Linux users, this Tor front-end lets you anonymously browse the Internet, send instant messages and e-mail, and more. Operating System: Linux.