Sunday, February 19, 2012

How to help your kids use social websites more safely

These days, many kids draw little distinction between real life and online life. They may use social websites designed for children such as Webkinz or Club Penguin, or social websites designed for adults such as Windows Live Spaces, YouTube, MySpace, Flickr, Twitter, Facebook, and others. Whatever they're doing, they should understand that many of these web pages can be viewed by anyone with access to the Internet.


Kids can use these sites to:


=> Chat

=>  Play games

=>  Post and browse through photos and videos

=> Blog

=> Post an online profile

Unfortunately, some of the information kids post on their pages can also make them vulnerable to phishing scams, cyberbullying, and Internet predators. Here are several ways you can help your kids can use social websites more safely.

>>  Communicate with your children about their experiences. Encourage your children to tell you if something they encounter on one of these sites makes them feel anxious, uncomfortable or threatened. Stay calm and remind your kids they are not in trouble for bringing something to your attention. Let them know you will work with them to help resolve the situation for a positive outcome.

>>  Set your own house Internet rules. As soon as your children begin to use the Internet on their own, it is a good idea to come up with a list of rules for using the Internet that everyone can agree on. These rules should include whether your children can use social websites and how they can use them. For more information on setting rules, see Using family contracts to help protect your kids online.

>>   Ensure your kids follow age limits on the site. The recommended age for signing up for social websites is usually 13 and over. If your children are under the recommended age for these sites, do not let them use the sites. It is important to remember that you cannot rely on the services themselves to keep your underage child from signing up.



>>   Educate yourself about the site. Evaluate the sites that your child plans to use and make sure both you and your child understand the privacy policy and the code of conduct. Find out if the site monitors content that people post. Also, review your child's page periodically. For more suggestions, see Tips on blogging safely for parents and kids.


>>   Insist that your children never meet anyone in person that they've communicated with online only, and encourage them to communicate only with people they've met in person. Kids are in real danger when they meet strangers in person whom they've communicated with online only. You can help protect your children by encouraging them to use these sites to communicate with their friends, but not with people they've never met in person.
It might not be enough to simply tell your child not to talk to strangers, because your child might not consider someone they've "met" online to be a stranger. For more advice on protecting your children on the Internet, see Online predators: What you can do to minimize the risk.



>>   Ensure your kids don't use full names. Have your children use only their first names or a nickname, but not a nickname that would attract inappropriate attention. Also, do not allow your children to post the full names of their friends.


>>   Be wary of other identifiable information in your child's profile. Many social websites allow kids to join public groups that include everyone who goes to a certain school.
Be careful when your children reveal this and other information that could be used to identify them, such as their school mascots, their workplaces,or the name of the towns they live in. Too much information can make your children vulnerable to cyberbullying, Internet predators, Internet fraud, or identity theft. For more information, see Recognize phishing scams and fake emails.



>>   Consider using a site that is not very public. Some websites allow you to password-protect your site or use other methods to help limit viewers to only people your child knows. With Windows Live Spaces, for example, you can set permissions for who can view your site, ranging from anyone on the Internet to only people you choose.

>>   Be smart about details in photographs. Explain to your children that photographs can reveal a lot of personal information. Encourage your children not to post photographs of themselves or their friends with clearly identifiable details such as street signs, license plates on their cars, or the name of their school on their sweatshirts.



>>   Warn your child about expressing emotions to strangers. You've probably already encouraged your kids not to communicate with strangers directly online. However, kids use social websites to write journals and poems that often express strong emotions. Explain to your children that many of these words can be read by anyone with access to the Internet and that predators often search out emotionally vulnerable kids. For more information, see things you can teach kids to improve their web safety.


>>   Teach your children about cyberbullying. As soon as your children are old enough to use social websites, talk to them about cyberbullying. Tell them that if they think they're being cyberbullied, they should share this information right away with a parent, a teacher, or another adult that they trust. It's also important to encourage kids to communicate with other people online in the same way they would face-to-face. Ask kids to treat other people the way they would prefer to be treated.


>>   Removal of your child's page. If your children refuse to abide by the rules you've set to help protect their safety and you've attempted to help them change their behavior, you can contact the social website your child uses and ask them to remove the page. You may also want to investigate Internet-filtering tools (such as Windows Live Family Safety) as a complement to, not a replacement for, parental supervision.

Saturday, February 18, 2012

Protect your privacy on the Internet

Your privacy on the Internet depends on your ability to control both the amount of personal information that you provide and who has access to that information. To read about how your information gets on the Internet and how it is used, see Your information on the Internet: What you need to know.


Follow the practical advice below to help increase your privacy online.


Think before you share personal information
First, read the website's privacy policy


Privacy policies should clearly explain what data the website gathers about you, how it is used, shared, and secured, and how you can edit or delete it. (For example, look at the bottom of this and every page on Microsoft.com.) No privacy statement? Take your business elsewhere.


Do not share more than you need to


>>Do not post anything online that you would not want made public.

>>Minimize details that identify you or your whereabouts.

>>Keep your account numbers, user names, and passwords secret.

>>Only share your primary email address or Instant Message (IM) name with people who you know or with reputable organizations. Avoid listing your address or name on Internet directories and job-posting sites.

Enter only required information—often marked with an asterisk (*)—on registration and other forms.



Choose how private you want your profile or blog to be
Modify Windows Internet Explorer or website settings or options to manage who can see your online profile or photos, how people can search for you, who can make comments on what you post, and how to block unwanted access by others.


Monitor what others post

Search for your name on the Internet using at least two search engines. Search for text and images. If you find sensitive information on a website about yourself, look for contact information on the website and send a request to have your information removed.


Regularly review what others write about you on blogs and social networking websites. Ask friends not to post photos of you or your family without your permission. If you feel uncomfortable with material such as information or photos that are posted on others' websites, ask for it to be removed.


For more information, see Your information on the Internet: What you need to know.



Guard your information


Protect your computer
You can greatly reduce your risk of online identity theft by taking these three steps to protect your computer:

1.  Use an Internet firewall.

Note: Windows 7, Windows Vista, and Windows XP with Service Pack 2 and Service Pack 3 have a firewall already built in and automatically turned on.


2. Visit Microsoft Update to verify your settings and check for security updates.
Note Microsoft Update will also update your Microsoft Office programs.


3. Subscribe to antivirus software and keep it current. Microsoft Security Essentials is a free download for Windows 7, Windows Vista, and Windows XP. For more information, see Help protect your PC with Microsoft Security Essentials. For more information, see How to boost your malware defense and protect your PC.


Create strong passwords

1.Strong passwords are at least 14 characters long and include a combination of letters (both upper and lower case), numbers, and symbols. They are easy for you to remember but difficult for others to guess.


2.Don't share your passwords with friends.


3.Avoid using the same password everywhere. If someone steals it, all the information that password protects is at risk.



Tip Learn how to create strong passwords.


Save sensitive business for your home computer


Avoid paying bills, banking, and shopping on a public computer, or on any device (such as a laptop or mobile phone) over a public wireless network.
Tip Internet Explorer can help erase your tracks on a public computer, leaving no trace of specific activity. For more information, see InPrivate: Frequently asked questions.
Protect yourself from fraud


Spot the signs of a scam


Watch for deals that sound too good to be true, phony job ads, notices that you have won a lottery, or requests to help a distant stranger transfer funds. Other clues include urgent messages ("Your account will be closed!"), misspellings, and grammatical errors.


   1.Think before you click to visit a website or call a number in a suspicious email or phone message both could be phony.
    2.Be cautious with links to video clips and games, or open photos, songs, or other files—even if you know the sender. Check with the sender first.


Look for signs that a web page is safe


Before you enter sensitive data, check for evidence that:

  1.
The site uses encryption, a security measure that scrambles data as it crosses the Internet. Good indicators that a site is encrypted include a web address with https ("s" stands for secure) and a closed padlock beside it. (The lock might also be in the lower-right corner of the window.)

  2.You are at the correct site—for example, at your bank's website, not a phony website. If you are using Internet Explorer, one sign of trustworthiness is a green address bar like the one above.


Use a phishing filter
Find a filter that warns you of suspicious websites and blocks visits to reported phishing sites. For example, try the SmartScreen Filterincluded in Internet Explorer.


Help detect potential fraud


In the United States, you are entitled to one free credit report every year from each of the three major U.S. credit bureaus: Experian, Equifax, and TransUnion. Get them by visiting AnnualCreditReport.com.


Tip If you have been a victim of identity theft, find out what you can do about it.

Saturday, February 4, 2012

Port Control Protocol (PCP) Security

A fter the transition to Internet Protocol Version 6 (IPv6), hosts will often be behind IPv6 firewalls. But before the transition, mobile wireless devices will want to reduce their keepalive messages, and hosts of all sorts will share IPv4 addresses using a variety of address-sharing technologies. To meet these needs, the IETF formed the Port Control Protocol Working Group in August 2010 to define a new protocol for hosts to communicate with such devices. The initial output of this Working Group is the Port Control Protocol (PCP). Interoperability between two independently developed implementations of PCP was demonstrated at the IETF meeting in July 2011, highlighting the importance of this protocol to the industry. After it becomes a standard, PCP is expected to be deployed in various operating systems, IPv6 home gateways, IPv4 home gateways (Network Address Translators [NATs]), mobile third- and fourth-generation (3G and 4G, respectively) gateways (Gateway GPRS Support Nodes [GGSNs]), and Carrier-Grade NATs (CGNs).


Introduction to PCP
PCP performs two major functions: It allows packets to be received from the Internet to a host (such as to operate a server), and allows a host to reduce keepalive traffic of connections to a server. PCP can be extended in two ways: with new OpCodes or with new Options. The base PCP specification defines two OpCodes: map and peer , and defines several Options that can be carried with those OpCodes.
To operate a server, packets are sent from a host on the Internet to a server. The IP model expects devices to be connected to a network and be able to exchange packets with each other. However, few deployed networks actually permit hosts to receive packets from the Internet because of business needs (for example, to protect wireless spectrum from malicious or accidental packets originated on the Internet) or because of technology restrictions (for example, IPv4 address-sharing devices such as Network Address and Port Translators [NAPT]). To operate a server, a host uses the map OpCode.
To reduce keepalives, a host needs to send traffic before a middlebox will destroy an idle connection. Many middleboxes, such as firewalls or NATs, maintain state and will destroy mappings if the connection has been idle. Today, in order to prevent destruction of mappings, hosts send keepalive traffic to keep those mappings alive. The keepalive traffic has several disadvantages, including reduction of battery lifetime, network chatter, and server scalability (servers have to discard the keepalive traffic). PCP allows a host to determine how aggressively a middlebox will destroy an idle connection, allowing the host to reduce its keepalive traffic with the PEER OpCode.
PCP is encoded in binary and carried over the User Datagram Protocol (UDP), which eases implementation on clients and servers. The client is responsible for retransmitting messages, and all messages are idempotent. The PCP client can be part of the operating system (much like a Dynamic Host Configuration Protocol [DHCP] client or a Universal Plug and Play [UPnP] Internet Gateway Device Protocol [IGD] client) or the PCP client can be coded entirely in an application (much like any other application-level protocol such as the Network Time Protocol [NTP]). A major feature of PCP is its flexibility and simple messaging, so it can be implemented easily in a variety of systems and at high scale.

PCP Mapping IPv6 and IPv4



>>Security


When installing an IPv4 NAPT on a residential network, the NAPT has a side effect: it prevents unsolicited incoming traffic from reaching hosts inside the home. Traffic that originates inside the home can traverse the NAPT toward the Internet. This function is expected by many users to such a degree that when IPv6-capable routers were first installed on residential networks, users complained that their IPv6 hosts were seeing traffic from the Internet. This visibility meant that IPv6 printers, webcams, and other hosts had to be protected from malicious traffic from the Internet. Based on this experience, IPv6 Customer Premises Equipment (CPE) routers intended for installation in the residential market filter most unsolicited incoming traffic by default. Thus, IPv6 CPE routers provide filtering similar to what users experience today with IPv4 NAPT devices.


With both IPv4 NAPT and RFC 6092 IPv6 routers, outgoing traffic from a host creates a mapping that then allows bidirectional traffic to a specific (Transmission Control Protocol [TCP] or UDP) port on the internal host, meaning when a host sends a TCP SYN, a SYN ACK can be returned to the host. Neither IPv4 NAPT devices nor RFC 6092 IPv6 routers have to do any additional filtering of that mapping, and after that mapping is created will allow traffic from any host on the Internet to reach the internal host—not just traffic from that particular host. This lack of filtering is necessary for certain applications
to function.
PCP was built with a security model similar to that deployed on home networks. With PCP, a host can send a PCP packet requesting a mapping so that any host on the Internet can now initiate communications with the internal host. Similarly, without PCP, a host could send a TCP SYN from a specific port (for example, port 80), thereby creating a mapping nearly identical to a PCP mapping. As with sending a TCP SYN, PCP allows a host to open mappings only for itself, unless the network administrator has taken the extra step to enable the PCP THIRD_PARTY option.


You may wish to have additional restrictions for some networks. PCP is extensible to support authorization, and there is ongoing work to support authentication and authorization within PCP.
PCP is extensible and there are already several proposed extensions to the protocol, including a way to control which IP address pool is assigned to a mapping, bulk port allocation to optimize acquiring a large set of ports, and rapid recovery after NAT failure or network renumbering.



Sunday, January 1, 2012

Multifunctional malware, staged drive-by attacks to rise in 2012

Automated toolkits with business models that include rental agreements and constant updates will gain considerable improvements in 2012, with many attack kits being primed with new features that enable even the least tech-savvy cybercriminals to hone malware in 2012 for highly targeted attacks.

Financial malware designed to target and infiltrate bank accounts could be recoded for targeted non-financial attacks, according to Boston-based security vendor Trusteer. The Zeus and SpyEye codebases, which are now publicly available, can be manipulated to pull off more sophisticated targeted attacks against enterprises. “Over the next twelve months perimeters will face an onslaught from various sources, viruses going financial, APT-style technologies in Zeus code derivatives manipulated by new coders and in other commercially available malware kits,” Trusteer CTO Amit Klein noted in the company’s list of predictions. 


Cybersecurity career experts: Mobile app security skills hot in 2012

Enterprises are going to be on the hunt for security professionals with the skills and certifications required to embrace the explosive demand for mobile devices and the cocktail of mobile security threats associated with them, according to several security industry career experts.
Security job recruiters and career advisors predict that in 2012 the swelling attraction to smartphones, tablets and other mobile devices will trigger substantial growth in jobs requiring IT security expertise. In particular, organizations are keen to nail down applicants with skill sets related to developing and maintaining mobile app security and enforcing mobile device security policies, according to Jeff Snyder, president of Woodland Park, Colo.-based SecurityRecruiter.com.

“The applications are now being written for mobile devices, and that brings up some different issues,” Snyder said.

Enterprises have been too focused on network security issues over the last few decades and as a result, according to Snyder, few organizations have spent enough time on creating secure applications.


Saturday, December 31, 2011

New Network Security Challenges for 2012 Happy New Year

2012 will be the year that a cyberattack really does hit a public utility hard, taking down an electric grid. Along those same lines, industrial control systems in other countries will be rocked with a sustained cyberattack that will make Stuxnet look like child's play in a year that increasingly will find that cyber-sabotage and cyberwar are realities that must be reckoned with.

Sunday, December 25, 2011

How to avoid a costly mistake on a Christmas Eve


>>Never reveal your personal password to anyone, even payment companies


>>Ensure domain name matches the website name

>>Have up-to-date anti-virus, anti-malware and anti-spyware software on your computer

>>Check warranty conditions, product disclosures and shipping details.

"A fraudulent site selling TVs or video cameras will look very convincing," Choice spokeswoman Ingrid Just said in a statement today.
"This makes it hard to tell the difference between what's dodgy and what's not.
"It's worth taking a few seconds to verify the security certificate, especially when the site is one you're not familiar with."

*Shoppers are being told to look out for a small padlock symbol that appears beside the URL during payment process.

*This indicates that details should be secure, with shoppers able to click on the padlock to check the status of the retailer's security certificate.

*Another sign of a secure site is if an 's' appears in the website address - beginning with https//: - during the payment process.
The 's' is another indicator your information will be encrypted.

Internet Security for Christmas Presents

This Christmas has seen a large increase in the sales of new devices such as iPads, tabs, laptops, games consoles and smart phones. Fife Police are hoping that users obtain security software to protect themselves and their devices.
The most likely forms of attack on computers will involve 'phishing' and 'malware'. Phishing attacks will lead users to a website with the aim of obtaining personal information, such as bank accounts and passwords. Malware, or malicious software, enables criminals to infiltrate a computer and control it remotely, allowing them to use the computer for illegitimate purposes, for example, to steal personal information or send spam emails. Keeping the computers operating system and security software up-to-date is the most effective way of protecting your machine.


Parents and carers should also ensure that the children are sufficiently aware of the online risks particularly when engaging in social networking, instant messaging or online chat.
Detective Inspector Stuart Morris, e-crime Unit said: "A common sense approach has to be used online. Many scam offer deals that are tempting becs you think you are getting a bargain, so if it luks too good to be true, it probably is."


The 12 Internet scams of Christmas


A timely reminder of some security traps, some of which we see time and time and time again every year.


1. On the first day of Christmas, I downloaded an advent calendar that unleashed a virus attack on my computer.


Santa says: be very cautious of downloaded games and novelties unless from a trusted source, or you could find yourself with an unwanted security breach.

---------------------------------------------------------


2. On the second day of Christmas, I scanned a QR code with

Friday, December 23, 2011

Working from home, is your office data security compromised?

   In many cases executive IT and security professionals trust their Information Security departments to provide adequate security to protect employees while operating in their business environment. However it is rare for users to extrapolate this security to a home environment.What does this mean in practical terms? Well, an enterprise will normally provide a risk analysis of a security threat and then provide adequate controls to mitigate that risk to an acceptable level. And users need to consider the same things when at home. So what are the considerations which IT directors should take into account when looking at cyber security provisions for mobile workers?


Challenges
  • Complying with a growing number of regulations governing the handling and protection of customer data
  • Establishing consistent backups and reliable recovery with limited IT resources and network bandwidth
  • Dealing with exponential growth in data at remote sites, which makes wide-area network backups impractical
  • Minimizing high administrative costs associated with a backup applications and tape media at multiple remote sites
  • Reducing or eliminating the off-site transport of backup data on tapes from remote sites to other locations


Key security questions outlined below:

Monday, December 19, 2011

Network Anomaly Detection using Soft Computing



INTRUSION detection is based on the assumption that intrusion activities are noticeably different from normal system activities and thus detectable. As defined in, intrusion detection is “the process of monitoring the events
occurring in a computer system or network and analyzing them for signs of intrusions. It is also defined as attempts to compromise the confidentiality, integrity, availability, or to bypass the security mechanisms of a computer or network”. Anomaly Intrusion Detection Systems (IDSs) aim at distinguishing an abnormal activity from an ordinary one. Many approaches have been proposed which include statistical, machine learning, data mining and immunological inspired techniques. There are two main intrusion detection systems. Anomaly intrusion detection system is based on the profiles of normal behaviors of users or applications and checks whether the system is being used in a different manner.


Tuesday, November 15, 2011

CA-2001-22 W32/Sircam Malicious Code



Original release date: July 25, 2001

Last revised: August 23, 2001
Source: CERT/CC
A complete revision history can be found at the end of this file.

Systems Affected


  • Microsoft Windows (all versions)





  • Overview

    "W32/Sircam" is malicious code that spreads through email and potentially through unprotected network shares. Once the malicious code has been executed on a system, it may reveal or delete sensitive information.
    As of 10:00EDT(GMT-4) Jul 25, 2001 the CERT/CC has received reports of W32/Sircam from over 300 individual sites.

    I. Description

    W32/Sircam can infect a machine in one of two ways:

    Propagation Via Email

    The virus can appear in an email message written in either English or Spanish with a seemingly random subject line. All known versions of W32/Sircam use the following format in the body of the message:
    EnglishSpanish
    Hi! How are you?
           [middle line]
           See you later. Thanks
    
    Hola como estas ?
           [middle line]
           Nos vemos pronto, gracias.
    
    Where [middle line] is one of the following:
    English
    I send you this file in order to have your advice
    I hope you like the file that I sendo you
    I hope you can help me with this file that I send
    This is the file with the information you ask for
    
    Spanish
    Te mando este archivo para que me des tu punto de vista
    Espero te guste este archivo que te mando
    Espero me puedas ayudar con el archivo que te mando
    Este es el archivo con la informacion que me pediste
    
    Users who receive copies of the malicious code through electronic mail might recognize the sender. We encourage users to avoid opening attachments received through electronic mail, regardless of the sender's name, without prior knowledge of the origin of the file or a valid digital signature.
    The email message will contain an attachment whose name matches the subject line and has a double file extension (e.g.subject.ZIP.BAT or subject.DOC.EXE). The CERT/CC has confirmed reports that the first extension may be .DOC, .XLS, or .ZIP. Anti-virus vendors have referred to additional extensions, including .GIF, .JPG, .JPEG, .MPEG, .MOV, .MPG, .PDF, .PNG, and .PS. The second extension will be .EXE, .COM, .BAT, .PIF, or .LNK. The attached file contains both the malicious code and the contents of a file copied from an infected system.
    When the attachment is opened, the copied file is extracted to both the %TEMP% folder (usually C:\WINDOWS\TEMP) and the Recycledfolder on the affected system. The original file is then opened using the appropriate default viewer while the infection process continues in the background.


    W32/Sircam includes its own SMTP client capabilities, which it uses to propagate via email. It determines its recipient list by recursively searching for email addresses contained in all *.wab (Windows Address Book) files in the %SYSTEM% folder. Additionally, it searches the folders referred to by
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
    for files containing email addresses. All addresses found are stored in SC??.DLL or S??.DLL files hidden in the %SYSTEM% folder.
    W32/Sircam first attempts to send messages using the default email settings for the current user. If the default settings are not present, it appears to use one of the following SMTP relays:
    • prodigy.net.mx
    • NetBIOS name for 'MAIL'
    • mail.<defaultdomain> (e.g., mail.example.org)
    • dobleclick.com.mx
    • enlace.net
    • goeke.net

    Propagation Via Network Shares

    In addition to email-based propagation, analysis by anti-virus vendors suggests that W32/Sircam can spread through unprotected network shares. Unlike the email propagation method, which requires a user to open an attachment to infect the machine, propagation of W32/Sircam via network shares requires no human intervention.
    If W32/Sircam detects Windows networking shares with write access, it
    1. copies itself to \\[share]\Recycled\SirC32.EXE
    2. appends "@ win\Recycled\SirC32.exe" to AUTOEXEC.BAT
    If the share contains a Windows folder, it also
    1. copies \\[share]\Windows\rundll32.exe to \\[share]\Windows\run32.exe
    2. copies itself to \\[share]\Windows\rundll32.exe
    3. when virus is executed from rundll32.exe, it calls run32.exe

    Infection process

    1. When installed on a victim machine, W32/Sircam installs a copy of itself in two hidden files:
      • %SYSTEM%\SCam32.exe
      • Recycled\SirC32.exe
      Installing in Recycled may hide it from anti-virus software since some do not check this folder by default.
      Based on external analyses, there is also a probability that W32/Sircam will copy itself to the %SYSTEM% folder as ScMx32.exe. In that case, another copy is created in the folder referred to byHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup (the current user's personal startup folder). The copy created in that location is named Microsoft Internet Office.exe. When the affected user next logs in, this copy of W32/Sircam will be started automatically.
    2. The registry entry HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\Driver32 is set to%SYSTEM%\SCam32.exe so that W32/Sircam will run automatically at system startup.
    3. The registry entry HKEY_CLASSES_ROOT\exefile\shell\open\command is set to "C:\Recycled\SirC32.exe" "%1" %*", causing W32/Sircam to execute whenever another executable is run.
    4. A new registry entry, HKEY_LOCAL_MACHINE\Software\SirCam, is created to store data required by W32/Sircam during execution.
    5. W32/Sircam searches for filenames with .DOC, .XLS, .ZIP extensions in the folders referred to by

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop
      While the personal folder may vary with configuration, it is often set to \My Documents or\Windows\Profiles\%username%\Personal. A list of these files is stored in %SYSTEM%\scd.dll.





    6. W32/Sircam attaches its own binary to selected files it finds and stores the combined file in the Recycled folder.




    II. Impact

    W32/Sircam can have a direct impact on both the computer which was infected as well as those with which it communicates over email.
    • Breaches of confidentiality: The malicious code will at a minimum search through select folders and mail potentially sensitive files. This form of attack is extremely serious since it is one from which it is impossible to recover. Once a file has been publicly distributed, any potentially sensitive information in it cannot be retracted.
    • Limit Availibility (Denial of Service)
      • Fill entire hard drive: Based on external analyses, on any given day, there is a probability that it will create a file named C:\Recycled\sircam.sys which consumes all free space on the C: drive. A full disk will prevent users from saving files to that drive, and in certain configurations impede system-level tasks (e.g., swapping, printing).
      • Propagation via mass emailing: W32/Sircam will attempt to propagate by sending itself through email to addresses obtained as described above. This propagation can lead to congestion in mail servers that may prevent them from functioning as expected.NOTE: Since W32/Sircam uses native SMTP routines connecting to pre-defined mail servers, propagation is independent of the mail client software used.
    • Loss of Integrity: Published reports indicate that on October 16 there is a reasonable probability that W32/Sircam will attempt to recursively delete all files from the drive on which Windows is installed (typically C:).

    III. Solution

    Run and Maintain an Anti-Virus Product

    It is important for users to update their anti-virus software. Most anti-virus software vendors have released updated information, tools, or virus databases to help detect and partially recover from this malicious code. A list of vendor-specific anti-virus information can be found in Appendix A.
    Many anti-virus packages support automatic updates of virus definitions. We recommend using these automatic updates when available.

    Exercise Caution When Opening Attachments

    Exercise caution when receiving email with attachments. Users should never open attachments from an untrusted origin, or ones that appear suspicious in any way. Finally, cryptographic checksums should also be used to validate the integrity of the file.
    The effects of this class of malicious code are activated only when the file in question is executed. Social engineering is typically employed to trick a recipient into executing the malicious file. The best advice with regard to malicious files is to avoid executing them in the first place. The following tech tip offers suggestions as to how to avoid them:
    Protecting yourself from Email-borne Viruses and Other Malicious Code During Y2K and Beyond

    Filter the Email or use a Firewall

    Sites can use email filtering techniques to delete messages containing subject lines known to contain the malicious code, or they can filter all attachments.
    Likewise, a firewall or border router can be used to stop the W32/Sircam outbound SMTP connections to mail servers outside of the local network. This filtering strategy will prevent further propagation of the worm from a particular host when the local mail configuration is not used.

    Appendix A. - Vendor Information

    Aladdin Knowledge Systems

    http://www.esafe.com/home/csrt/valerts2.asp?virus_no=10068

    Central Command, Inc.

    http://support.centralcommand.com/cgi-bin/command.cfg/php/enduser/std_adp.php?p_refno=010718-000010

    Command Software Systems

    http://www.commandsoftware.com/virus/sircam.html

    Computer Associates

    http://www.cai.com/virusinfo/encyclopedia/descriptions/s/sircam137216.htm

    Data Fellows Corp

    http://www.datafellows.com/v-descs/sircam.shtml

    McAfee

    http://vil.mcafee.com/dispVirus.asp?virus_k=99141&

    Norman Data Defense Systems

    http://www.norman.com/virus_info/w32_sircam.shtml

    Panda Software

    http://www.pandasoftware.es/vernoticia.asp?noticia=987

    Proland Software

    http://www.pspl.com/virus_info/worms/sircam.htm

    Sophos

    http://www.sophos.com/virusinfo/analyses/w32sircama.html

    Symantec

    http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html

    Trend Micro

    http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=TROJ_SIRCAM.A

    Computer security risks to home users

    A. What is at risk?
    Information security is concerned with three main areas:

    >Confidentiality -  information should be available only to those who rightfully have access to it

    >Integrity --  information should be modified only by those who are authorized to do so

    >Availability --  information should be accessible to those who need it when they need it

    These concepts apply to home Internet users just as much as they would to any corporate or government network. You probably wouldn't let a stranger look through your important documents. In the same way, you may want to keep the tasks you perform on your computer confidential, whether it's tracking your investments or sending email messages to family and friends. Also, you should have some assurance that the information you enter into your computer remains intact and is available when you need it.

    Some security risks arise from the possibility of intentional misuse of your computer by intruders via the Internet. Others are risks that you would face even if you weren't connected to the Internet (e.g. hard disk failures, theft, power outages). The bad news is that you probably cannot plan for every possible risk. The good news is that you can take some simple steps to reduce the chance that you'll be affected by the most common threats -- and some of those steps help with both the intentional and accidental risks you're likely to face.

    Before we get to what you can do to protect your computer or home network, let’s take a closer look at some of these risks.


    B.     Intentional misuse of your computer

    The most common methods used by intruders to gain control of home computers are briefly described below. More detailed information is available by reviewing the URLs listed in the References section below.




    > Trojan horse programs
    >Back door and remote administration programs
    >Denial of service
    >Being an intermediary for another attack
    >Unprotected Windows shares
    >Mobile code (Java, JavaScript, and ActiveX)
    >Cross-site scripting
    >Email spoofing
    >Email-borne viruses
    >Hidden file extensions
    >Chat clients
    >Packet sniffing






    C.     Accidents and other risks




    In addition to the risks associated with connecting your computer to the Internet, there are a number of risks that apply even if the computer has no network connections at all. Most of these risks are well-known, so we won’t go into much detail in this document, but it is important to note that the common practices associated with reducing these risks may also help reduce susceptibility to the network-based risks discussed above.




    1.  Disk failure
    Recall that availability is one of the three key elements of information security. Although all stored data can become unavailable -- if the media it’s stored on is physically damaged, destroyed, or lost -- data stored on hard disks is at higher risk due to the mechanical nature of the device. Hard disk crashes are a common cause of data loss on personal computers. Regular system backups are the only effective remedy.




    2.  Power failure and surges
    Power problems (surges, blackouts, and brown-outs) can cause physical damage to a computer, inducing a hard disk crash or otherwise harming the electronic components of the computer. Common mitigation methods include using surge suppressors and uninterruptible power supplies (UPS).




    3.  Physical Theft
    Physical theft of a computer, of course, results in the loss of confidentiality and availability, and (assuming the computer is ever recovered) makes the integrity of the data stored on the disk suspect. Regular system backups (with the backups stored somewhere away from the computer) allow for recovery of the data, but backups alone cannot address confidentiality. Cryptographic tools are available that can encrypt data stored on a computer’s hard disk. The CERT/CC encourages the use of these tools if the computer contains sensitive data or is at high risk of theft (e.g. laptops or other portable computers).

    Monday, November 14, 2011

    Steam hack confirmed by Valve game company

    Steam, the online gaming network run by game company Valve, confirmed Thursday that its forums had been hacked and warned users to keep a close eye on their credit card statements.

    The service’s forums had been defaced earlier in the week, resulting in some gamers receiving e-mails from a hacking Web site, Kotaku report


    Gallery




     In recent years, lawmakers and advocacy groups have made increased efforts to protects users’ privacy online. Here are some cases that helped stoke the debate about tracking and privacy on the Web.

    On Thursday, Valve co-founder Gabe Newell left a message on the company’s forums confirming the intrusion, saying that all forum passwords will be reset and adding that the attack “goes beyond the Steam forums.” While there is evidence of a deeper intrusion, the company is not yet requiring all Steam users to reset their account passwords, which are separate from forum accounts.

    “We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked,” Newell wrote. “We are still investigating.”

    He added that there have been no reports that Steam accounts were compromised, but advised users to change their passwords as a precaution.

    “I am truly sorry this happened, and I apologize for the inconvenience,” he said.

    The intrusion comes at a bad time for Steam, which is not only premiering a major title — Bethesda’s “Elder Scrolls V: Skyrim” — Friday, but is also facing long-term challenges from Electronic Arts’ Origin service, cloud gaming service OnLive and an as-yet-unreleased online service from retailer GameStop.

    Security, understandably, is the most pressing issue facing these services as they ask gamers to trust their saved data, credit cards and other personal information to off-site servers. Companies are also jumpy following the Sony data hack that pulled the PlayStation Network and Sony Online Entertainment services off line for a month and resulted in a lot of bad press for the electronics giant.

    7 Things You Need To Know About Recent Web Hack Attacks

    By Jeremiah Grossman
    Citigroup, Sony, PBS, Sega, Nintendo, Gawker, AT&T, the Central Intelligence Agency, the United States Senate, NASA, Nasdaq, the NYSE, Zynga, BBC Music, the Royal Navy, and thousands of others have one thing in common – they have all fallen victim to hack attacks in the last year.
    Jeremiah Grossman
    Millions of credit-card numbers, customers’ personal information and records, not to mention gigabytes worth of intellectual property, have been compromised. And the onslaught shows no signs of stopping. The net result has been stark – hundreds of millions of dollars in corporate losses, sharp stock price declines, lawsuits, fines and costly downtime. Most alarmingly, it no longer matters whether a company is in financial services, retail, education, gaming, social networking, government, telecom, media or travel – no industry is immune to these breaches.

    Sunday, November 13, 2011

    8 Steps To Keep Your PCs Safe From Online Criminals

    By Mike Cote
    Mike Cote
    is vice president at Dell Secureworks.
    Mike Cote

    With the diversity of security attacks globally, it is becoming increasingly difficult and complex for small and medium-sized businesses to assemble the right in-house resources to protect themselves against the cyber threats they face, whether it’s a data breach through the network, data leakage by employees, or lost laptops or mobile devices. We have also seen an uptick in the number of court cases, where SMBs have had six-figure amounts stolen out of their bank account by cyber thieves. The liability for these breaches is being shifted to the CIOs and IT managers, as SMBs are being accused of not taking the appropriate precautions to protect their data. The need for comprehensive information security is more pressing now than ever before.

    Saturday, November 12, 2011

    Homes & Small Businesses Network security tips

    1. A basic firewall or a unified threat management system. 
    2. For Windows users, basic Antivirus software. An anti-spyware program would also be a good idea. There are many other types of antivirus or anti-spyware programs out there to be considered. 
    3. When using a wireless connection, use a robust password. Also try to use the strongest security supported by your wireless devices, such as WPA2 with AES encryption. 
    4. If using Wireless: Change the default SSID network name, also disable SSID Broadcast; as this function is unnecessary for home use. (However, many security experts consider this to be relatively useless).[5] 
    5. Enable MAC Address filtering to keep track of all home network MAC devices connecting to your router. 
    6. Assign STATIC IP addresses to network devices. 
    7. Disable ICMP ping on router. 
    8. Review router or firewall logs to help identify abnormal network connections or traffic to the Internet. 
    9. Use passwords for all accounts. 
    10. For Windows users, Have multiple accounts per family member and use non-administrative accounts for day-to-day activities. 
    11. Disable the guest account[citation needed] 
    12. Raise awareness about information security to children

    Friday, November 11, 2011

    Want to Enable GodMode in Windows 7? Here's how !!!

    I thought this was a joke when I read it, but evidently not. If you want a quick way to get to all the settings on Windows 7 at a SINGLE PLACE.
    Then. 
    GodMode is a great trick that allows you to access all Windows 7 configuration options from one location.
    Windows 7 users are all abuzz about the OS and its GodMode. If you haven't heard of it, GodMode is a feature that was revealed by CNet's Microsoft Correspondent, Ina Fried. GodMode is a folder that brings together a long list of customization settings allowing you to change all your settings from one place. Neat huh? It's very easy to enable and damn useful if you tweak things around a lot.


    I've broken it down into five-step process to avoid confusion:


    Step 1: Right click.


    Step 2: Click create folder.


    Step 3: Rename Name your  folder this to :-
    GODMOD.{ED7BA470-8E54-465E-825C-99712043E01C}


    Step 4: Blink as the folder changes form to look like the control panel.