Archive for the ‘Security’ Category

What Do All Those Computer Security Words Mean? (In Layman’s Terms)

Friday, October 29th, 2010

This blog article is reposted in part, with permission, from the SANS Ouch! Newsletter.

[Editor's Note: (Wyman) This month we present an overview of why and how the Bad Guys do it, what it's called, and what you can do to protect your computer.]

Blackhats. Hackers who use their skills for explicitly criminal or other malicious ends, such as writing malware (malicious software) to steal
credit card numbers and banking data or by phishing; a.k.a. the Bad Guys.

Phishing. The practice of sending out fake email messages that look as if they come from a trusted person or institution-usually a bank-in
order to trick people into handing over confidential information. The emails often direct you to a website that looks like that of the real
financial institution. But it is a fake and has been rigged to collect your personal information, such as passwords, credit card numbers and
bank account numbers, and transmit them to the Bad Guys.

Man-in-the-middle. An attack in which a criminal hacker intercepts information sent between your computer and the website of your financial
institution and then uses that information to impersonate you in cyberspace. The hacker is able to defeat even very sophisticated
security measures and gain access to your account.

Botnet. Botnets consist of large numbers of hijacked computers that are under the remote control of a criminal or a criminal organization. The
hijacked computers-a.k.a. “zombies” or “bots” (short for “robots”) -are recruited using viruses spread by email or drive-by downloads. Worms are used to find and recruit additional computers. The biggest botnets consist of thousands and even millions of computers, most often
unprotected home computers.

Virus. A malicious program that usually requires some action on the part of a user in order to infect a computer; for example, opening an
infected attachment or clicking on a link in a rigged email may trigger a virus to infect your computer.

Drive-by Download. A kind of malware that installs itself automatically when you visit a booby-trapped website. Symptoms of a drive-by download include: your homepage has been changed, unwanted toolbars have been added, and unfamiliar bookmarks appear in your browser.

Worm. Self-replicating malware that, for instance, hunts down unprotected computers and recruits them for criminal or other malicious
purposes. Unlike a virus, worms do not require any action on your part in order to infect your computer.

Fake Anti-Virus. Fake anti-virus software purports to be a helpful program than can find and remove malware, but in fact it is malware–the
very thing that it’s supposed to eliminate. After taking over your computer, it pretends to do security scans, tells you it has found
malware, and then asks you to pay to have the non-existent malware removed. Whether or not you pay, fake anti-virus is likely to install
more malware.

Whitehats. Hackers who use their skills for positive ends, and often for thwarting blackhats. Many whitehats are security professionals who spend their time identifying and fixing vulnerabilities in software that blackhats seek to exploit for criminal or other malicious purposes.

Security suite. A set of software applications designed to protect your computer that consists of anti-virus, anti-malware and a personal
firewall.

Anti-virus and anti-malware. Helpful software applications that scan your computer for certain patterns of infection. The patterns they scan
for are the signatures, or definitions, of known forms of malware. Since Bad Guys are creating new forms of malware continuously, it is important that you keep your anti-virus and anti-malware definitions updated. See
the “Patches and Updates” section below.

Personal firewall. Software that monitors incoming and outgoing traffic on your computer and checks for suspicious patterns indicating the
presence of malware or other malicious activity. A personal firewall alerts you to these threats and attempts to block them. Like anti-virus
and anti-malware software, personal firewalls require frequent updates to provide effective protection.

Updates. Security software relies on frequent updates in order to be able to counteract previously undetected forms of malware. Consequently, your computer may suffer a “window of vulnerability” between the time a new form of malware is identified and the time when your security software can block it or remove the infection. Set your security software to update automatically.

Patches. Operating systems, like Windows and OS X, and software applications, such as Internet Explorer and Firefox, may be found to contain security flaws or holes that make your computer vulnerable to attack. Their makers release patches to plug the holes. The fastest and surest way to get these installed quickly is to use auto-updating via the Internet. Some software applications require manual updating. See the “Patches and Updates” section below.

Black Tuesday a.k.a. Patch Tuesday. On the second Tuesday of each month Microsoft releases security patches for Windows, Internet Explorer, Office and its other software products. You can have these installed automatically using Microsoft Update. See the “Patches and Updates” section below.

Auto-updating. A software tool built into Windows (“Microsoft Update”) and OS X (“Auto Update”) and many other applications which can download and install important security updates and patches for software installed on your computer automatically. See the “Patches and Updates” section below.

More information:
http://www.binaryfarm.com/jargon.html
http://besafe.more.net/sam/resources/jargon.pdf
http://ittraining.iu.edu/workshops/win_security/terminology.html

What is the Difference Between Log Off, Restart, and Shut Down?

Tuesday, October 26th, 2010

A concept users frequently have difficulty understanding is the difference between “logging off” a system, “restarting a system,” and “shutting down” a system. This article will clear that up. (more…)

Information Disclosure That Affects You

Wednesday, October 13th, 2010

I go to great lengths to keep my email addresses safe from spammers. One reason that I, as a general rule, refuse to put a real email address into a website’s contact form, give it out to mailing lists, etc., is because once your address is out, you never know where it will end up, and the spam floodgates are open. (more…)

An Example of Why Your Password is Yours and Yours Alone

Friday, September 17th, 2010

Today I participated in an investigation which led to the termination of employment at a client location. The employer cited numerous violations of company policy, including, among others, inappropriate use of company computers for personal use, e.g., spending time on Facebook, Craigslist, and Match.com for non-business purposes. (more…)

Windows 2000 End of Life

Tuesday, July 13th, 2010

Today marks the end of life (all forms of support) for Windows 2000 and Windows XP Service Pack 2. This means that, while new threats and bugs will continue to be found in these operating systems for some time, they will receive no further updates from Microsoft.

If you are still running these at your business or at home, an upgrade is called for as soon as possible.

Google Dumps Windows (At Least, Unofficially)

Friday, June 4th, 2010

This Financial Times article reports that Google, without question one of the Internet’s strongest influences today, has decided to ditch Windows and move employees to Macintosh and Linux PCs. This move is reportedly largely due to the January hacks on Google and many other corporations, allegedly originating from China. Windows has a long-standing perceived history of having a worse security track record than its competition, and a large part of this comes because it’s simply the largest attack surface. Not surprisingly, the same thing that makes it the most widely developed-for platform for applications keeps it the highest profile target for malware and security exploits as well.

I applaud this move toward security and productivity. I don’t think it will be a easy task for Google, but I believe it will be worth the effort in the long run.

Does your company need to consider switching away from Windows?

Safe Browsing Tip: Mozilla Plugin Check

Monday, May 24th, 2010

The Mozilla project recently expanded their popular and successful (and free) Plugin Check service to support non-Mozilla browsers. So now, not only does this service, which scans your browser’s settings for outdated plugins, e.g., Adobe Flash Player, work with Firefox, but also with Opera, Google Chrome, Apple Safari, and even, to a limited extent, Microsoft Internet Explorer. Given that unpatched client software, especially operating systems, browsers, and browser plugins, remain the top cyber-security concern today, everyone should stop what they’re doing and go to Mozilla Plugin Check right now.

Still Think You Want Those Admin Rights Over Your PC? Think Again.

Monday, May 10th, 2010

In case you missed a previous post or two on the topic of why end users should not have administrative rights over their PCs, BeyondTrust has released a very compelling report on this issue. But first, let me ask the reader a few questions. (more…)

Malware Being Distributed by Mainstream Websites

Monday, March 29th, 2010

On this article from Digital Trends, some of the most popular websites on the Internet have been (unintentionally) serving up malware ia the ad networks that they subscribe to. (more…)

Answers to Yesterday’s Password Quiz

Tuesday, February 23rd, 2010

In yesterday’s post, we offered a quiz to rate your password IQ. Here are the answers. (more…)