Phishing


                                          Formate of Phishing Messages
You open an email or text, and see a message like this:
"click to login in orkut"
"Choose your net banking and login from your mailbox"
"We suspect an unauthorized transaction on your account. To ensure that your account is not compromised, please click the link below and confirm your identity."
"During our regular verification of accounts, we couldn't verify your information. Please click here to update and verify your information."
“Our records indicate that your account was overcharged. You must call us within 7 days to receive your refund.”
The senders are phishing for your information so they can use it to commit fraud.
How to Deal with Phishing Scams

Delete email and text messages that ask you to confirm or provide personal information (credit card and bank account numbers, Social Security numbers, passwords, etc.). Legitimate companies don't ask for this information via email or text.[Phishing]
The messages may appear to be from organizations you do business with – banks, for example. They might threaten to close your account or take other action if you don’t respond.[Phishing]
Don’t reply, and don’t click on links or call phone numbers provided in the message, either. These messages direct you to spoof sites – sites that look real but whose purpose is to steal your information so a scammer can run up bills or commit crimes in your name.[Phishing]
Area codes can mislead, too. Some scammers ask you to call a phone number to update your account or access a "refund." But a local area code doesn’t guarantee that the caller is local.[Phishing]
If you’re concerned about your account or need to reach an organization you do business with, call the number on your financial statements or on the back of your credit card.[Phishing]
Action Steps
You can take steps to avoid a phishing attack:
Use trusted security software and set it to update automatically. In addition, use these computer security practices.[Phishing]
Don't email personal or financial information. Email is not a secure method of transmitting personal information.[Phishing]
Only provide personal or financial information through an organization's website if you typed in the web address yourself and you see signals that the site is secure, like a URL that begins https (the "s" stands for secure). Unfortunately, no indicator is foolproof; some phishers have forged security icons.[Phishing]
Review credit card and bank account statements as soon as you receive them to check for unauthorized charges. If your statement is late by more than a couple of days, call to confirm your billing address and account balances.[Phishing]
Be cautious about opening attachments and downloading files from emails, regardless of who sent them. These files can contain viruses or other malware that can weaken your computer's security.[Phishing]
Content Taken from other website

Latest computer security threat


Latest 10 virus alerts
1 Troj/Mdrop-DKE
2 Troj/Sasfis-O
3 Troj/Keygen-FU
4 Troj/Zbot-AOY
5 Troj/Zbot-AOW
6 W32/Womble-E
7 Troj/VB-FGD
8 Troj/FakeAV-DFF
9 Troj/SWFLdr-W
10 W32/RorpiaMem-A
Top 10 viruses in October 2011
1 Troj/Invo-Zip
2 W32/Netsky
3 Mal/EncPk-EI
4 Troj/Pushdo-Gen
5 Troj/Agent-HFU
6 Mal/Iframe-E
7 Troj/Mdrop-BTV
8 Troj/Mdrop-BUF
9 Troj/Agent-HFZ
10 Troj/Agent-HGT
Top 10 virus hoaxes
1 Hotmail hoax
2 Budweiser frogs screensaver
3 Bonsai kitten
4 Olympic torch
5 MSN is closing down
6 A virtual card for you
7 Meninas da Playboy
8 Bill Gates fortune
9 JDBGMGR
10 Justice for Jamie

How to kill malicious processes


Using safe mode
Most of malicious processes are inactive when PC operates in safe mode with networking. To reach safe mode with networking, do following:
Reboot
Press F8 early on (you can press F8 couple times)
Choose Safe mode with networking (preferably) or safe mode from menu
On success you should not see any alerts that bother you under normal mode
Killing processes using task manager
The benefit of using task manager is that you do not need to download anything. Task manager is present in all windows computers, though it might be disabled and provides little control


Open task manager by either pressing ctrl+shift+esc or pressing ctrl+alt+del and choosing from menu. For best results, try doing so just after windows login, while other processes are still loading
If it fails, go to go to Start->Run and type taskmgr
If this fails, go to C:\Windows\System32, copy taskmgr and rename it to 1.scr , 1.com or other random name. Launch that file. You can try right-clicking on it and choosing Run as administrator on Windows Vista or Windows 7
Choose process TAB, choose to see processes of all users (optional)
Choose malicious process from the list, right click on it
Press End process
On successful stop of malicious processes alerts should disappear and you can continue to next steps of malware removal.
Killing processes using process explorer
Process explorer provides more information on how the processes were launched. Also it is not blocked together with Task Manager. If it is blocked from execution, try saving it as 1.scr, 1.com or iexplore.exe before execution.


Download Process explorer from here : http://download.sysinternals.com/Files/ProcessExplorer.zip and unzip.
Launch process explorer (procexp.exe )
Select malicious process and press DEL.
On successful stop of malicious processes alerts should disappear and you can continue to next steps of malware removal.

Removing Security Shield Virus

Removing Security Shield can be accomplished. You must use our custom made free program called nuke-M to disable the virus. After disabling the virus you need to run PC Tools to scan and fully remove the infection from your computer. Security Shield makes several registry modifications as well as system file modifications. PC Tools will fix all of the issues that the Security Shield virus has caused.
The instructions below are the fastest and easiest way to remove the Security Shield Virus.


Begin Virus Removal by Following the Instructions Below
Target Virus: Security Shield Virus
The removal process we are illustrating below has been proven to be the most effective way to remove the Security Shield Virus.
You must be on the infected computer when performing these steps.
1.On your keyboard, click and hold the Windows key, then press the R key. See keyboard diagram below.
2.After you have clicked the Window key and R key, the Run Box will appear. Type the following into the run box and click OK:
                                   iexplorehttp://www.spywarehelpcenter.com/nuke
After you click OK, your computer will connect to our website and download nuke-M.
3.After you have saved the nuke-M file to your desktop, go ahead and run the nuke-M file by double clicking on it. If you computer asks if you are sure you want to run nuke-M, click OK. nuke-M will quickly disable the virus allowing you to install antivirus software. The virus should now be temporarily disabled. If the nuke-M file is blocked by the virus, rename the file to ‘iexplore’ or ‘explorer’ and try to open nuke-M again.
4.Now that the virus is not running it is time to begin removal. On your keyboard, click and hold the Windows key, then press the R key. See keyboard diagram below.
5.After you have pressed the Windows and R key, the Windows Run Box will open.Type the following into the run box and click OK:
                                          iexplore http://www.spywarehelpcenter.com/remove
After clicking OK, your computer will connect to our website and download our recommended virus removal program called Spyware Doctor by PC Tools. When the download box appears click the Save button.
6.Open the PC Tools installation file from your desktop and perform the virus scan.
7.Once the virus scan is complete, PC Tools will have found Security Shield. Remove the Security Shield Virus by registering PC Tools. You must register PC Tools to remove Security Shield.
8.After you have registered PC Tools the Security Shield Virus should be completely gone.





Security Shield Virus


 It is program or software which is used to steal money from your computer.Almost all type of operating system has infected from from security shield virus.There is some way or set of rule to remove this virus from computer.To uninstall this software from computer we must know which type of file can infect from security shield virus as well as we must know what type of alert it will show

                             Security Shield infects your computer through the downloading of an infected file. The commonly named infected file for this particular virus is FastAntivirus2011.exe. If you have download this file, do not open or run it under any circumstances. If you run the infected file you will fall victim to the Security Shield Virus.Security Shield is specifically designed to make you believe that it is a real antivirus and security program. It will show numerous alerts, fake scans, fake scan results and more. All of the alerts and fake scans are a scare tactic. Security Shield will claim that you have numerous infections on your computer in an attempt to have you purchase it

The Security Shield Virus sole purpose is to steal your money. The entire charade of fake scans and fake infection alerts are an attempt to have you purchase the registered version of Security Shield. Please know that there is no such thing as a registered version of Security Shield. Do not enter your credit card information into the purchase display under any circumstances.

Computer Security


1 Protect your personal information. It's valuable.
2 Know who you're dealing with.
3 Use security software that updates automatically.
4 Keep your operating system and Web browser up-to-date, and learn about their security features.
5 Keep your passwords safe, secure, and strong.
6 Back up important files.
7 Learn what to do in an e-mergency.
Access to information and entertainment, credit and financial services, products from every corner of the world — even to your work — is greater than ever. Thanks to the internet, you can play a friendly game with an opponent across the ocean; review and rate videos, songs, or clothes; get expert advice in an instant; or collaborate with far-flung co-workers in a "virtual" office.
But the internet — and the anonymity it affords — also can give online scammers, hackers, and identity thieves access to your computer, personal information, finances, and more.
With awareness as your safety net, you can minimize the chance of an internet mishap. Being on guard online helps you protect your information, your computer, and your money. To be safer and more secure online, make these seven practices part of your online routine.
1. Protect your personal information. It's valuable.
To an identity thief, your personal information can provide instant access to your financial accounts, your credit record, and other assets. If you think no one would be interested in YOUR personal information, think again. ANYONE can be a victim of identity theft. In fact, according to the Federal Trade Commission, millions of people become victims every year. Visit ftc.gov/idtheft to learn what to do if your identity is stolen or your personal or financial information has been compromised – online or in the "real" world.
How do criminals get your personal information online? One way is by lying about who they are, to convince you to share your account numbers, passwords, and other information so they can get your money or buy things in your name. The scam is called "phishing": criminals send email, text, or pop-up messages that appear to come from your bank, a government agency, an online seller or another organization with which you do business. The message asks you to click to a website or call a phone number to update your account information or claim a prize or benefit. It might suggest something bad will happen if you don't respond quickly with your personal information. In reality, legitimate businesses should never use email, pop-ups, or text messages to ask for your personal information.
To avoid phishing scams:
Don't reply to an email, text, or pop-up message that asks for personal or financial information, and don't click on links in the message. If you want to go to a bank or business's website, type the web address into your browser yourself.
Don't respond if you get a message – by email, text, pop-up or phone – that asks you to call a phone number to update your account or give your personal information to access a refund. If you need to reach an organization with which you do business, call the number on your financial statement, or use a telephone directory
Some identity thieves have stolen personal information from many people at once, by hacking into large databases managed by businesses or government agencies. While you can't enjoy the benefits of the internet without sharing some personal information, you can take steps to share only with organizations you know and trust. Don't give out your personal information unless you first find out how it's going to be used and how it will be protected.
If you are shopping online, don't provide your personal or financial information through a company's website until you have checked for indicators that the site is secure, like a lock icon on the browser's status bar or a website URL that begins "https:" (the "s" stands for "secure"). Unfortunately, no indicator is foolproof; some scammers have forged security icons. And some hackers have managed to breach sites that took appropriate security precautions.
Read website privacy policies. They should explain what personal information the website collects, how the information is used, and whether it is provided to third parties. The privacy policy also should tell you whether you have the right to see what information the website has about you and what security measures the company takes to protect your information. If you don't see a privacy policy — or if you can't understand it — consider doing business elsewhere.
2. Know who you're dealing with.
And what you're getting into. There are dishonest people in the bricks and mortar world and on the internet. But online, you can't judge an operator's trustworthiness with a gut-affirming look in the eye. It's remarkably simple for online scammers to impersonate a legitimate business, so you need to know who you're dealing with. If you're thinking about shopping on a site with which you're not familiar, do some independent research before you buy.
If it's your first time on an unfamiliar site, call the seller's phone number, so you know you can reach them if you need to. If you can't find a working phone number, take your business elsewhere.
Type the site's name into a search engine: If you find unfavorable reviews posted, you may be better off doing business with a different seller.
Consider using a software toolbar that rates websites and warns you if a site has gotten unfavorable reports from experts and other internet users. Some reputable companies provide free tools that may alert you if a website is a known phishing site or is used to distribute spyware.
File-Sharing: Worth the hidden costs?
Every day, millions of computer users share files online. File-sharing can give people access to a wealth of information, including music, games, and software. How does it work? You download special software that connects your computer to an informal network of other computers running the same software. Millions of users could be connected to each other through this software at one time. Often, the software is free and easy to access.
But file-sharing can have a number of risks. If you don't check the proper settings, you could allow access not only to the files you intend to share, but also to other information on your hard drive, like your tax returns, email messages, medical records, photos, or other personal documents. In addition, you may unwittingly download malware or pornography labeled as something else. Or you may download material that is protected by the copyright laws, which would mean you could be breaking the law.
If you decide to use file-sharing software, be sure to read the End User Licensing Agreement to be sure you understand and are willing to tolerate the potential risks of free downloads.
3. Use security software that updates automatically.
Keep your security software active and current: at a minimum, your computer should have anti-virus and anti-spyware software, and a firewall. You can buy stand-alone programs for each element or a security suite that includes these programs from a variety of sources, including commercial vendors or from your Internet Service Provider. Security software that comes pre-installed on a computer generally works for a short time unless you pay a subscription fee to keep it in effect. In any case, security software protects against the newest threats only if it is up-to-date. That's why it is critical to set your security software to update automatically.
Some scam artists distribute malware disguised as anti-spyware software. Resist buying software in response to unexpected pop-up messages or emails, especially ads that claim to have scanned your computer and detected malware. That's a tactic scammers have used to spread malware. OnGuardOnline.gov can connect you to a list of security tools from legitimate security vendors selected by GetNetWise, a project of the Internet Education Foundation.
Once you confirm that your security software is up-to-date, run it to scan your computer for viruses and spyware. If the program identifies a file as a problem, delete it.
Anti-Virus Software
Anti-virus software protects your computer from viruses that can destroy your data, slow your computer's performance, cause a crash, or even allow spammers to send email through your account. It works by scanning your computer and your incoming email for viruses, and then deleting them.
Anti-Spyware Software
Installed on your computer without your consent, spyware software monitors or controls your computer use. It may be used to send you pop-up ads, redirect your computer to websites, monitor your internet surfing, or record your keystrokes, which, in turn, could lead to the theft of your personal information.
A computer may be infected with spyware if it:
Slows down, malfunctions, or displays repeated error messages
Won't shut down or restart
Serves up a lot of pop-up ads, or displays them when you're not surfing the web
Displays web pages or programs you didn't intend to use, or sends emails you didn't write.
Firewalls
A firewall helps keep hackers from using your computer to send out your personal information without your permission. While anti-virus software scans incoming email and files, a firewall is like a guard, watching for outside attempts to access your system and blocking communications to and from sources you don't permit.
Don't Let Your Computer Become Part of a "BotNet"
Some spammers search the internet for unprotected computers they can control and use anonymously to send spam, turning them into a robot network, known as a "botnet." Also known as a "zombie army," a botnet is made up of many thousands of home computers sending emails by the millions. Most spam is sent remotely this way; millions of home computers are part of botnets.
Spammers scan the internet to find computers that aren't protected by security software, and then install bad software – known as "malware" – through those "open doors." That's one reason why up-to-date security software is critical.
Malware may be hidden in free software applications. It can be appealing to download free software like games, file-sharing programs, customized toolbars, and the like. But sometimes just visiting a website or downloading files may cause a "drive-by download," which could turn your computer into a "bot."
Another way spammers take over your computer is by sending you an email with attachments, links or images which, if you click on or open them, install hidden software. Be cautious about opening any attachments or downloading files from emails you receive. Don't open an email attachment — even if it looks like it's from a friend or coworker — unless you are expecting it or know what it contains. If you send an email with an attached file, include a text message explaining what it is.
4. Keep your operating system and Web browser up-to-date, and learn about their security features.
Hackers also take advantage of Web browsers (like Firefox or Internet Explorer) and operating system software (like Windows or Mac's OS) that don't have the latest security updates. Operating system companies issue security patches for flaws that they find in their systems, so it's important to set your operating system and Web browser software to download and install security patches automatically.
In addition, you can increase your online security by changing the built-in security and privacy settings in your operating system or browser. Check the "Tools" or "Options" menus to learn how to upgrade from the default settings. Use your "Help" function for more information about your choices.
If you're not using your computer for an extended period, disconnect it from the internet. When it's disconnected, the computer doesn't send or receive information from the internet and isn't vulnerable to hackers.
5. Protect your passwords.
Keep your passwords in a secure place, and out of plain sight. Don't share them on the internet, over email, or on the phone. Your Internet Service Provider (ISP) should never ask for your password.
In addition, hackers may try to figure out your passwords to gain access to your computer. To make it tougher for them:
Use passwords that have at least eight characters and include numbers or symbols. The longer the password, the tougher it is to crack. A 12-character password is stronger than one with eight characters.
Avoid common words: some hackers use programs that can try every word in the dictionary.
Don't use your personal information, your login name, or adjacent keys on the keyboard as passwords.
Change your passwords regularly (at a minimum, every 90 days).
Don't use the same password for each online account you access.
6. Back up important files.
If you follow these tips, you're more likely to be free of interference from hackers, viruses, and spammers. But no system is completely secure. If you have important files stored on your computer, copy them onto a removable disc or an external hard drive, and store it in a safe place.
7. Learn what to do in an e-mergency.
If you suspect malware is lurking on your computer, stop shopping, banking, and other online activities that involve user names, passwords, or other sensitive information. Malware could be sending your personal information to identity thieves.
Confirm that your security software is up-to-date, then use it to scan your computer. Delete everything the program identifies as a problem. You may have to restart your computer for the changes to take effect.
If the problem persists after you exhaust your ability to diagnose and treat it, you might want to call for professional help. If your computer is covered by a warranty that offers free tech support, contact the manufacturer. Before you call, write down the model and serial number of your computer, the name of any software you've installed, and a short description of the problem. Your notes will help you give an accurate description to the technician.
If you need professional help, if your machine isn't covered by a warranty, or if your security software isn't doing the job properly, you may need to pay for technical support. Many companies — including some affiliated with retail stores — offer tech support via the phone, online, at their store, or in your home. Telephone or online help generally are the least expensive ways to access support services — especially if there's a toll-free helpline — but you may have to do some of the work yourself. Taking your computer to a store usually is less expensive than hiring a technician or repair person to come into your home.
Once your computer is back up and running, think about how malware could have been downloaded to your machine, and what you could do to avoid it in the future.
Also, talk about safe computing with anyone else who uses the computer. Tell them that some online activity can put a computer at risk, and share the seven practices for safer computing.

Internet security

1. Use a firewall
We strongly recommend the use of some type of firewall product for Internet security, such as a network appliance or a personal firewall software package. Intruders are constantly scanning home user systems for known vulnerabilities. Network firewalls (whether software or hardware-based) can provide some degree of protection against these attacks.
2. Don't open unknown email attachments[ Internet security]
Before opening any email attachments, be sure you know the source of the attachment. It is not enough that the mail originated from an address you recognize. The Melissa virus spread precisely because it originated from a familiar address. Malicious code might be distributed in amusing or enticing programs. [ Internet security]
If you must open an attachment before you can verify the source, we suggest the following procedure:

a. save the file to your hard disk
b. scan the file using your antivirus software
c. open the file
For additional protection, you can disconnect or lock your computer's network connection before opening the file.
Following these steps will reduce, but not wholly eliminate, the chance that any malicious code contained in the attachment might spread from your computer to others.
3. Don't run programs of unknown origin
Never run a program unless you know it to be authored by a person or company that you trust. Also, don't send programs of unknown origin to your friends or coworkers simply because they are amusing -- they might contain a Trojan horse program. These programs seriously hurt Internet Security.

4. Disable hidden filename extensions
Windows operating systems contain an option to "Hide file extensions for known file types". The option is enabled by default, but you can disable this option in order to have file extensions displayed by Windows. After disabling this option, there are still some file extensions that, by default, will continue to remain hidden.
There is a registry value which, if set, will cause Windows to hide certain file extensions regardless of user configuration choices elsewhere in the operating system. The "NeverShowExt" registry value is used to hide the extensions for basic Windows file types. For example, the ".LNK" extension associated with Windows shortcuts remains hidden even after a user has turned off the option to hide extensions.[ Internet security]

5. Keep all applications, including your operating system, patched
Vendors will usually release patches for their software when a vulnerability has been discovered. Most product documentation offers a method to get updates and patches. You should be able to obtain updates from the vendor's web site. Read the manuals or browse the vendor's web site for more information.
Some applications will automatically check for available updates, and many vendors offer automatic notification of updates via a mailing list. Look on your vendor's web site for information about automatic notification. If no mailing list or other automated notification mechanism is offered you may need to check periodically for updates.[ Internet security]

6. Turn off your computer or disconnect from the network when not in use
Turn off your computer or disconnect its Ethernet interface when you are not using it. An intruder cannot attack your computer if it is powered off or otherwise completely disconnected from the network.[ Internet security]

7. Disable Java, JavaScript, and ActiveX if possible
Be aware of the risks involved in the use of "mobile code" such as ActiveX, Java, and JavaScript. A malicious web developer may attach a script to something sent to a web site, such as a URL, an element in a form, or a database inquiry. Later, when the web site responds to you, the malicious script is transferred to your browser.[ Internet security]
The most significant impact of this vulnerability can be avoided by disabling all scripting languages. Turning off these options will keep you from being vulnerable to malicious scripts. However, it will limit the interaction you can have with some web sites.
Many legitimate sites use scripts running within the browser to add useful features. Disabling scripting may degrade the functionality of these sites.[ Internet security]

8. Disable scripting features in email programs
Because many email programs use the same code as web browsers to display HTML, vulnerabilities that affect ActiveX, Java, and JavaScript are often applicable to email as well as web pages. Therefore, in addition to disabling scripting features in web browsers, we recommend that users also disable these features in their email programs. It is important to Internet security.[ Internet security]

9. Make regular backups of critical data
Keep a copy of important files on removable media such as ZIP disks or recordable CD-ROM disks (CD-R or CD-RW disks). Use software backup tools if available, and store the backup disks somewhere away from the computer.[ Internet security]

10. Make a boot disk in case your computer is damaged or compromised
To aid in recovering from a security breach or hard disk failure, create a boot disk on a floppy disk which will help when recovering a computer after such an event has occurred. Remember, however, you must create this disk before you have a security event.[ Internet security]

11. Consult your system support personnel if you work from home
If you use your broadband access to connect to your employer's network via a Virtual Private Network (VPN) or other means, your employer may have policies or procedures relating to the security of your home network. Be sure to consult with your employer's support personnel, as appropriate, before following any of the steps outlined in this document.[ Internet security]
Taken from armor2net.com

Enterprise resource planning(ERP) Security

                                   Introduction
Every good hacker story ends with the line: "and then he's got root access to your network and can do whatever he wants." But the story really doesn't end there. This is just the beginning of the real damage that the hacker can inflict.While most information security initiatives focus on perimeter security to keep outsiders from gaining access to the internal network, the potential for real financial loss comes from the risk of outsiders acting as authorized users to generate damaging transactions within business systems.
The continued integration of enterprise resource planning software only increases the risk of both hackers who break through perimeter security and insiders who abuse system privileges to misappropriate assets - namely cash - through acts of fraud.
Security in the e-business, integrated enterprise resource planning (ERP) world requires a new way of thinking about security - not just about the bits and bytes of network traffic, but about business transactions that inflict financial losses from systems-based fraud, abuse and errors.
The ERP market has matured to a point where heightened competition has brought declining sales. As a result, ERP vendors are committed to bundling new functionality, such as CRM and Web services-based architecture, to provide more value to their customers.
Historically, ERP security focused on the internal controls that aim to limit user behavior and privileges while organizations rely on network perimeter defenses - firewalls, VPNs, intrusion detection, etc. - to keep outsiders from accessing the ERP system. However, increasingly integrated information systems with numerous system users require new levels of transaction-level security.
And while ERP systems allow enterprises to integrate information systems with trusted partners through supply chain management, the number of authorized users continues to grow. This effectively introduces new entry points to business systems from outside the traditional IT security perimeter. Enterprises must not only trust the actions of employees but also trust partners' employees and perimeter security.
Security in an ERP World:-For most enterprises, ERP security starts with user-based controls where authorized users log in with a secure username and password. Enterprises then limit a user's system access based on their individual, customized authorization level. For example, an accounts payable clerk should not have access to human resources or inventory management modules within the ERP system
Most ERP systems offer data encryption which limits someone's ability to export the database but does not address the need to protect authorized insiders from accessing unauthorized modules in the system.
Audit logs within an ERP system track individual transactions or changes in the system but provide little detail into the relevance of the transaction. With each transaction documented individually, the audit log does not consider the context of the transaction, such as the events that occurred before or after the transaction. Internal auditors can then sample the audit logs for irregular transactions.
However, about half of all organizations do not configure their ERP system to maintain audit logs because they are concerned about performance degradation and they don't think they need it. Regrettably, these organizations believe IT security only focuses on the layers of traditional perimeter security. In a compromise between security and performance, enterprises can avoid logging every detail of system activity and focus on meaningful information that's relevant to the transaction.For organizations that do utilize audit logs, system administrators can configure customized audit reports that employ simple logic to identify "outliers" - system transactions that fall outside of normal parameters, such as date and time, location of the user logging into the system and checks larger than a predefined setting.
While it's time consuming to customize these reports, they provide hundreds of data points to manually process and are invariably riddled with false positives. Each flagged event requires manual human analysis of the event because the audit reports cannot analyze the event to determine the cause for concern.
Security Failures
When you consider that the average business loses 3 percent to 6 percent of annual revenue due to fraud, most agree that the ERP security features listed above are not working. Worse yet, businesses suffer additional losses through duplicate payment errors. The average enterprise submits duplicate payments for 2 percent of its total accounts payable. Of these duplicate payments, 10 percent are never recovered, which leads to total losses equivalent to 0.2 percent of total accounts payable.
The fact remains that applications remain highly vulnerable to external security threats. Weak passwords can be broken with simple dictionary attacks; buffer overflows can flood an application until it allows a hacker in the door. However, some of the most damaging hacks come in the form of social engineering where users are tricked into freely divulging their credentials. And of course, the real danger of external hackers comes once they enter the system as authorized users with the ability to divert payments for their benefit.
Most organizations fail in their ERP security efforts because they implement systems with a plan that leaves controls design and implementation until the end of the process. However, ERP projects are invariably over budget and behind schedule, so strict internal controls are often glossed over to keep costs down and make up time.
Some organizations decide against stringent controls because internal controls can introduce additional overhead by making it hard for employees to do their jobs with process inefficiencies.
The biggest drawback of relying on internal controls for ERP security comes from the costly and time-consuming maintenance of those controls. As employees are promoted, reassigned or terminated, organizations must continually update their business systems with each employee's correct authorization level. The advent of new business partners, the creation of new business departments or entry into new markets also requires new or modified procedural rules. Maintenance of the ERP system can turn into a never-ending resource drain.
Taken from-internet solution

Speak ASIA: BUSTED Here is proof ?


The company name is: SpeakAsia Online Pte Ltd.formerly known as : Haren Technology Pte. Ltd.formerly known as: PAN Automotives Pte. Ltd.(Compliance rating for this company is Non Compliant currently)Prior to this name they were operating under:
 HAREN VENTURES PTE. LTD.
f.k.a HAREN AUTO PARTS PTE. LTD.
f.k.a HAREN MULTICONSULT TRADE SERVICES PTE. LTD.


Source: www.psi.gov.sg

I asked one of my CA friend that how frequently a company change it names and he said its very less and not done so frequently. There are 2 more companies with the same name whose status is either Cancelled or Terminated and again they keep changing their company name:

HAREN AUTO & HEAVY EQUIPMENTS
f.k.a HAREN AUTOMOTIVES & COMPONENTS And
 HAREN MULTICONSULT TRADE SERVICES




And there is a defunct website too: http://www.hmtservices.com/ where we can find the products they were dealing before starting this business which is no where related to online surveys or dotcoms. Check out the page http://www.hmtservices.com/sparts.htm  (probably they didnt had an active webmaster or the designer left work half complete due to several reasons)

b) When doing little more research on the address of the company the same address is used for different companies. A simple Google can throw a few names which I am listing below. Some of the companies having the same address are:

Valves.Com Pte Ltd
http://imageshack.us/m/573/8770/valves.jpg

SBS Consulting Pte. Ltd.
http://imageshack.us/m/805/5417/sbsgroup.jpg
http://img19.imageshack.us/img19/3762/unledrh.jpg ---> thanks metiz for the image

c) The company has a franchisee model so at the face of it you are not paying anything directly to the company "Speak Asia" and it goes in the name of the franchise (bank account) and who further pass that money to someone in Mumbai and all get to keep a certain % out of it. If its such a big company they should provide an option to pay online through credit card directly to them instead of making so m
d) If you watch YouTube for their Torch Bearers 2011 meet they are talking about opening a TV Channel by August 2011. Very nice and ambitious plan but doesnt it require a lot of regulatory processes and time and huge "money". But the ground reality is that they dont have a single registered office in India. There are claims that it will be open in May 2011 in Mumbai.

e) I found it amusing that they were using a hosted software at SurveyMonkey as their survey tool and only recently purchased Novi Survey. If its an established proven business with multi million dollars in revenue they should have built the survey system completely inhouse on which their entire business model works.

f) They claim they are established in Singapore / Malaysia / Indonesia but after doing a lot of research I didnt find enough evidence that proves that they are getting enough traffic from any of these countries to prove their claim. They are mainly in India and Bangladesh only.

i) Well many do beleive its a great opportunity and many feel its like a Ponzi scheme. If its the latter then how the whole thing works and how long it will last:

Well if we assume that company is not making money much out of these surveys and just running a ponzi scheme where the going is good till the flow of incoming people is great and keeps paying the subscribers them their own money and the new people who joined this affair. How will that work out:

For the first three month it is actually just paying out your own money back. So for the company there is always a buffer time of 3 months for the people to even realize how they have been gamed / duped. To keep the ship sailing they need to double their signups every quarter which is luckily happening for them SmileSo that they can pay the earlier and current customers from that money and keep some money for advertisement to maintain their signup targets.
So what will happen once the company falls short of their target of adding more people to its subscribers list?

 The first thing will be that there will be a rate cut in the surveys. Secondly we see less frequent surveys and at the end there will be hardly any surveys. The company is liable to pay only when you participate and fill the survey and as an user you cant sue the company as they are not liable to pay anything to you in the event there are no surveys. The initial 11,000 (which is soon going to be 15000) is towards the E-Zine so you continue to get that E-Zine
What happens when the company stops Surveys or doesnt pay?

Well nothing can be done due to the following reasons:



  • The main company is registered in Singapore so to recover 11000 hardly anyone will travel to Singapore to file a case against them in Singapore Court.
  • The company is selling you E-Zine and you have paid 11000 towards that and not towards the Survey. Your payment of Rs.1000 / 2 surveys is toward the Surveys you fill. So on that ground too the company is safe.
  • Lets assume something goes wrong and the Indian authorities goes after this whole scheme and in that case the company can easily bail themselves out saying they have not recieved any money from them cause none of the payments is made in their name rather its in the name of the Franchisee who are paid a certain % to forward that to the main distributor and who further pass it to someone else. So the person you can only catch is the person to whom you made the payment. But sadly the problem is that even that person is the victim of this whole scheme.
  • Yes one do receive a online reciept for the money that one pays from Speak Asia and here is the screenshot. Earlier it was given from "Online Surveys Today" which I doubt that any such company even exists though the address was same as SpeakAsia Online Pte. Ltd. and later it is changed to Haren Ventures Pte. Ltd. but they changed the address to a new address.
So how can someone run such a huge thing without anyone noticing it:

This is India and anything is possible. We easily believe in such schemes and are really fond of such online money making schemes.
 I leave the discretion of whether its an opportunity or a scam or something else on the readers to decide.
 Well when we search the internet there are several bloggers who have voiced their opinion on whether it is some scam or an opportunity but they all have been bombarded by comments of people who have all the reasons to believe its a genuine scheme and do not want anyone to distrupt the ongoing party.Well till the point every one is getting paid who really cares what goes behind the scene.  But we feel its important for us to ask some questions if we have reasons to believe that it CAN be scam in the making. 


If you all feel that this story is worth sharing please share it with all your friends and on Social Networks and this might help us spread more awareness about this.

 Working on orkut security, I know that fraudulent sites sometimes try to take advantage of orkut users like you and me. To help make sure that everyone is able to have a fun and safe experience on the site, I thought I'd share a few quick tips that I've picked up during my time on the orkut team. A bunch of these might seem like no-brainers, but hopefully you'll learn something new here as well:
  • Create a tough password: While "yourname123" is always a tempting password to create, keep in mind that it's just as easy for a malicious user to figure out as it is for you to remember. Try creating a password that involves a combination of letters and numbers that no one could easily guess, even if they know basic details about who you are. The same goes for your security question (the question that pops up if you forget your password)– you should try your best to pick a question that only you can answer.
  • Keep your private details private: Never share your orkut username and password with friends or on a site not authenticated by Google. orkut does not allow any external sites to store orkut login information and will never request that you enter it anywhere outside of the orkut login page. To be on the safe side, always check that your address bar reads "https://www.google.com/accounts/ServiceLogin?....." and nothing else when sharing your orkut user name and password.
  • Leave the coding to the engineers: Never copy and paste code into your address bar, no matter what it claims to be able to do. Typically these scripts actually send messages (in your name!) to your friends trying to trick them into giving up their personal information.
  • Downloads and orkut don't mix: Never download any file off of orkut, especially those that end in '.vb' or '.exe'. These files are often viruses that can infect your computer and start sending thousands of spam messages on your behalf. Sites offering special orkut themes or skins are particularly risky.
  • Think twice about external links: Links to sites outside of orkut that appear in scraps or posts have not been verified by the orkut team, and could lead you to harmful sites. We'd recommend only clicking on links that go to trusted sites or those that are from other orkut users you know well.
  • Anti-Virus software is always a good call: Even the most conscientious orkuteer can fall victim to a phishing attack, so it's important to always be alert and prepared. Regularly scanning your computer with updated anti-virus software is a great way to keep your computer secure.
  • For new orkut features, check out apps!: Sometimes an unofficial site may claim to offer special orkut features, but these sites are known for taking over orkut accounts and directly violate our Terms of Service. If you're looking for fun new orkut functionality, check out the thousands of applications that we have available. All of these apps have been built by talented developers according to standards that we believe will help to keep you safe online. If you haven't visited the app directory recently, take a look– you might be surprised at how much cool stuff you find.

via orkut blog