Find more Phishing Funda....

Loading
Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Saturday, August 16, 2008

How Did This Happen to Me? Top 10 Ways to Get Spyware or Viruses on Your Computer

If you use the internet, you have probably been infected with a virus, trojan or spyware. According to the SANS Internet Storm Center, the average unprotected PC is infected within 20 minutes of normal internet usage. Many people want to know what they did to get infected. Unfortunately, usually it was just one wrong click.

Here are the top reasons people get infected and how to prevent these common internet security threats.

10. Exchanging files in chat rooms.

You should never download files from sources you don’t trust. Viruses and other internet security threats can look like valid files or photos. Always scan files with a virus scanner before opening them.

9. Clicking on popup ads.

If you’re like most people, you probably don’t like popup ads. But whether you like them or not, you should never click on them. Popup ads can take you to a website that secretly downloads adware onto your computer. Enabling a popup blocker on your computer can help protect you. Some popups come from adware programs that have downloaded onto your computer, so if you still see popups after installing a popup blocker, scan your computer for spyware or adware.

8. Email attachments.

Viruses can be sent out as email attachments to infect your computer if you open them. If you download your email into an email program, scan all email attachments with a virus scanner. Most major webmail programs scan attachments before you download them, but you should still not download files from unknown sources. “Phishing” email, claiming to be from your bank or other financial institution which asks you to provide personal information or download something to your computer is another common email threat.

7. Instant messaging.

Because people are cautious with email attachments, new viruses are spreading through instant messaging programs. Infections look like valid files or photos, so always be careful accepting file transfers, even from sources you trust.

6. Downloading music.

Many websites that advertise free music downloads are loaded with spyware. You can even get spyware from these websites without manually starting a download. Other sites make you accept a spyware download to get the music you want.

5. Browsing websites.

Some websites use “drive-by downloads” – misleading dialogue boxes to secretly install spyware programs. Sometimes spyware can install even if you do not choose “yes” or “accept”. Keep your browser security settings on default to protect yourself against these infections.

4. Installing free programs or screen savers.

Check the license agreement of any program you install to confirm it does not come bundled with other programs. License agreements are supposed to explain if the software you are downloading will cause advertisements or other downloads. These programs may have long or confusing license agreements where they have buried this information. Always carefully read what you agree to before you download free software.

3. Adult-related websites.

Many of these sites make a profit by forcing viewers to download spyware and adware to access their site. You may not be able to view these sites if you are using a secure browser or have your security settings too high.

2. P2P programs like Kazaa or Limewire.

If you share music using peer-to-peer networks, you may be forced to download advertising software onto your computer. This software can generate popups from within your computer. In these cases, you may see popups even if you are not online.

1. Gaming websites.

It may seem that viewing spoilers for online games will let you win faster, but it can slow down your computer with spyware. Mick Lathrop, part of StopSign’s Spyware Research team says, “I get most of my spyware samples from gaming-related websites.” Avoid any site that requires a software download to access information.

Even if you have an anti-virus product on your computer, confirm that it protects against the growing threat of spyware. Enable a popup blocker and firewall for further protection. Using safe browsing habits and good security software can keep you safe on the internet.

Friday, June 20, 2008

How to Manage Your Username and Password The Easy and Secure Way

Have been an Internet user for more than 9 years, I have 100's
of logins and passwords to keep. I'm paranoid. I'm now even
more paranoid after I joined YMMSS because I use online payment
systems on weekly basis if not daily.

I used to use Microsoft Excel to manage my usernames, passwords,
and other registration information, both online and offline.
Excel is not safe because there are programs to crack password
protected Excel workbooks and I even cracked the spreadsheet and
VBA source code password for one of my old Excel financial
models I developed. Today I still use Excel to store some personal
information but I only save the Excel file on my another
PC that is not connected to Internet.

In my article "6 Essential Steps to Protect Your Computer On the
Internet", I highly recommended the award winning RoboForm. Free
version of RoboForm (http://www.roboform.com) does come with
limitations such as 10 Passcards only. If you don't want to buy
the Pro version (costs $29.99 as of my writing), there is an
easy-to-use freeware (see below) you can download right now and
manage unlimited usernames and passwords.

Download freeware Password Safe from SourceForge.net - the Open
Source community.

https://sourceforge.net/projects/passwordsafe/

Here are some great features of Password Safe:

- No installation is required. Simply download and double click the
pwsafe.exe file.

- Easy portable. Just copy and paste the EXE file and .dat database
file to any disks. Be aware that when you open Password Safe in
the other disk, you need to specify the database file location
(the .dat file).

- One master password unlocks an entire password database that can
contain all your other passwords.

- Grouping. Usernames and passwords can be grouped into different
categories you define, eg. Email Address, Payment, etc. You are in
total control.

- Strong, random password generation.

- Copy username and password to clipboard so that you don't have to
type them. Always keep in mind that you should never type any
username and password.

- Browse to URL. With one click, the URL related to your username
and password can be opened in your default web browser. Another
save on typing.

- You can create more than one password database (but you have to
memorize more than one master password. Not recommended.)

Here are some tips of using Password Safe (version 2.04) and
managing password in general.

Tip #1 - Always create a strong master password (Safe Combination
as used in the software).

Strong password should meet the following criteria:

- At least 8 characters long to prevent cracking. The longer the better.

- The password should contain lowercase, uppercase, numeric, and any
other characters that are available on keyboard.

- Ideally you should not use any meaningful words or numbers in the
password. Totally random password is the best.

Tip #2 - Let PasswordSafe generate random password for you.

To generate random password:

- Click the menu item Edit.

- Select Add Entry (or use corresponding icon button).

- When the dialogue window opens, on the right hand side, you can
see a Random Password Generate button. Click it, a random password
will be automatically inserted in the Password field.

The generated random password is constructed according to the password
policy defined in Password Safe. You can modify the default policy.

- Click the menu item Manage.
- In the dropdown menu, click Options.
- Click the Password Policy tab.
- Change the policy based on the strong password criteria stated above.

Some sites only allow alphanumeric passwords so make sure you select
the appropriate check boxes when this is the case.

Tip #3 - Very Important: Never type your master password when open
PasswordSafe.

Keylogger spyware can record keystrokes.

How can you enter master password without typing? I do this.

Step 1: Open a Notepad file (.txt).

Step 2: Copy and paste an article from any Internet website to
this .txt file.

Step 3: Select characters from this article and copy, paste to form your
master password.

Tip #4 - Very Important: Never lose your master password.

I memorize my master password. In addition, I also physically write it
down to a hand written study material that has my previous uni works.
Among the 1,000's of words, I placed my 22 characters master password
in two different pages in encrypted format that can let me derive
my master password.

Tip #5 - Categorize username and password.

When you add a new entry, you need to specify Group, Title,
Username, Password, and Notes. The entries that share the same Group
name will be gathered together automatically.

One Group can contain another Group as its sub Group. For example,
I have Email Address group which contains three sub-groups as
Friend, Work, Family.

Tip #6 - For security reasons, always use Copy Username to
Clipboard and Copy Password to Clipboard.

Remember, never type username and password on a web form. This is how
to do it.

- Highlight an entry.

- Right click mouse.

- In the pop-up menu, select Copy Username to Clipboard or Copy Password
to Clipboard

- Go to your login form, paste the username or password.

You can use mouse to do copy and paste. If you prefer short-cut keys,
this is how.

Copy: Ctrl+C
Paste: Ctrl+V

Tip #7 - Use "Browse to URL" rather than typing URL in browser address bar.

When you enter a new entry or edit an existing one, you can enter a URL
(must start with http://) at the first line in the Notes field. You can save website login
page's URL in this field. When you need to open a login page in browser,
right click the entry and click Browse to URL in the pop-up menu. Then
the login page will be opened in your default web browser automatically.

Tip #8 - Don't forget to backup your password database file.

Use the Make Backup menu item to save a second copy of your password file.

Tip #9 - Store your backups in a different offline computer or location.

This is a widely used backup strategy.

Tip #10 - Use the Notes field to store as many information as you want. Very handy for memo.

If you don't have two computers, you need to use other storage media
to save a second copy of your backup file and version them by date
(easy to track back). Other storage media can be zip drive,
thumb drive, floppy disk, CD, etc.

Off site backups are also important. Don't overlook this. You lose
all your data if you lose both your computer and your other
storage media all together for any reason.

Many companies provide online storage services for a fee. You can
store any digital files (you should password protect these files
first) on their secure servers. Search Google and you will find a lot.

I have two computers. One is used to surf net and it does not have any
sensitive info stored on it. Another one is for my development work
(not connected to Internet) and it has my backup files. I also store
my backups in a thumb drive and CDs sometimes.

Sunday, June 1, 2008

Passwords or Pass Phrase? Protecting your Intellectual Property

Much has been said on the theory of password protection for files, computer login, and other network access. In the past we used a combination of letters, special characters, and other techniques to try and prevent unwanted or unauthorized access to our computers, resources, and networks. A new theory on passwords is emerging that may help us remember our access codes, be more secure, and generally keep hackers and thieves out of our networks.

A password is a combination of words, letters, and special characters that only the user knows, allowing access to a computer or other information resources. As humans we have a large number of codes and numbers we need to remember every day – such as the key lock on our apartment entries, national identification numbers, automobile license or tag numbers, telephone numbers – it is a large and confusing suite of items we need to memorize.

When selecting a new password or pass code for access to a computer system, most of us understand how difficult it is to remember complex codes, and thus we select something already know n to us, such as names, birthdays, national identifiers, or other known items, and then place a number or character in front of the name or number thinking it is secure. This is easy to understand, as most of us simply do not have an ability to instantly recall large numbers of complex codes.

In a worst case we simply write down the complex code on a piece of paper, and leave it in a desk, our pocketbook, or in many cases taped to the front of our computer monitor.

However, to a hacker this makes access to your network or computer much easier, at they generally only have to learn a couple things about you, and add a few numbers to the front or ending of your personal data – you would be surprised how often this grants access to computers and networks. Ad some good “cracking utilities” to the hacker’s suite of tools, and you can understand the threat.

PassPhrases are a concept that will help us create more secure, easy to remember safeguards for our computer and network resource protection. A passphrase is a selection of words and/or numbers that are 15 characters or more in length, and are easy for us to remember. A couple examples of a good pass phrases are:

• igotodalaieejdaily

• shehasbeautifulhair

• surfinginhawaiiisgreat

According to Mark Minasi, a noted security consultant, a 15 character pass phrase will require a cracking program the following number of computations to try and break a 15 character pass phrase:

• 15 lowercase letters = 1,677,259,342,285,725,925,376 possibilities

• Try a million a second, it’ll take 531,855 centuries/years to break the code

As you can see, this is a pretty good level of security for your resource.

Another concern with passwords is if you forget or lose the password, and are using a utility like Microsoft’s Encrypting File System (EFS), you run the risk of losing all access to your important files if you require a hardware reset of your password. All EFS encrypted files are linked to your login profile, meaning if you encrypt a directory or file with EFS, and you do a hardware reset on your computer, those files and directories are lost FOREVER.

For Microsoft Windows users you can now also use spaces within your pass phrase, however we would not recommend embedding spaces in your pass phrase, as that actually does allow a cracker better access to getting your code – it may help them crack it in 100,000 years rather than 250,000!

Saturday, May 24, 2008

Delete Cookies: New-Age Diet or Common Sense Internet Security?

No, this article isn't about some new, lose-20-pounds-in-a-week, certified-by-some-tan-Southern-California-doctor diet. It's about cookies on your computer - what they are, why they are there, and what to do about them. Computer cookies actually have quite a bit in common with their baked counterparts - some are good, some are bad, and they have expiration dates.

Cookies are small text files that a server places onto your hard drive whenever you access a given domain. Cookies typically contain information that the website uses to either customize the page you are viewing or otherwise make your web browsing experience more convenient and enjoyable. The information is stored on your hard drive and accessed whenever you go back to the website that originally gave you the cookie. They usually include an expiration date at which point they will be erased from your computer - it could be when you close your browser; or hours, days, months, or years after it is placed. Some don't expire at all. At the time of this writing I had a cookie stored on my computer that wasn't set to expire until Wednesday, February 25th, 2195 at 3:45:13 am - I deleted it.

Before you run out to your browser's options and delete and block all cookies, let me mention a few common uses of cookies:

* Cookies store information for 'shopping carts' at online stores. When you select an item and place it in the shopping cart, a cookie is created to remember the item and the price so that you can keep shopping. When you are done shopping you simply click the button to check out and the site accesses the information stored in the cookies to complete your order.

* Cookies can be used to remember logins and passwords. While this initially sounds a little disheartening, the purpose is really to save you time. Sites will remember the information for you so you don't have to type it in each time you want to access information.

* Cookies help websites customize their content and layout for you. If you are a diehard fan of the local college's basketball team, and you always access the stats and score from the game at a website, that site might use a cookie to send you straight to your team's page.

* Cookies help identify whether you have already visited a site. They can also count how many times you have visited the site in a given period of time.

* Cookies remember the last page or position you were on at the site. Like a virtual bookmark, this is especially helpful if you are reading online or accessing several pages of information.

There are many other ways cookies can be used, and there is obvious potential for abuse. You probably wouldn't eat a cookie given to you by a complete stranger, especially if you didn't know what was in it. The same common-sense principle holds true while you're online, and exercising a little caution can save you from a lot of heartache later on. Blocking any and all cookies will guarantee no personal information is leaked through the cookies, but many sites will either not be able to or will choose not to interact with you.

The trick, then, is to let the good cookies through while screening out the bad ones, not at all dissimilar to what you do when you hover over the cookie tray at a party - you take the ones you want and leave the rest behind. This can be accomplished in a few different ways.

First, you can periodically delete all the cookies on your hard drive. This will systematically wipe out all unwanted cookies that have made their way to your computer. Unfortunately, it will also take care of all the good cookies too. If you only use the internet occasionally (i.e. a few minutes a week), this option might work for you.

Second, you can try to go about it manually. Many browsers that allow you to block cookies also include a feature that allows you to include a list of sites from which you will allow cookies. The advantage of this method is it places virtually complete control over cookies into your hands, allowing only those that you want to be placed on your hard drive. The disadvantage is that it can become very burdensome (at times downright annoying) having to constantly update the list of allowed sites.

Third, you can call in some third-party software to help out. The best programs will scan your computer to find all the cookies and put them into a table or list. This saves you the trouble of having to dig around your hard drive to find the files yourself (try looking for a folder named "Cookies"). Many programs will also indicate with some degree of confidence whether a given cookie is wanted or unwanted, and provide a convenient way to delete the ones that you decide you don't want.

Tuesday, May 20, 2008

Temporary Internet Files - the Good, the Bad, and the Ugly

A little bit of time invested into learning about internet security can go a long way in preventing mishaps on your computer. Temporary internet files are not something we should be afraid of, but we should certainly be careful in how much we trust them and how we deal with them.

Temporary internet files are image, text, and formatting files that are stored on your hard drive by the websites that you visit. They are placed there by the websites without your having to do anything. The files are stored on your computer the first time you visit the site so that the next time you go to that webpage you only have to load new information or files that have changed since the last time you visited - files that have not changed are loaded from the temporary internet files folder at a much faster speed than over the internet.

This seems like an incredibly appealing option, especially to those of us still working at home on dial-up connections (my teenage brother-in-law insists I'm "old school" because I don't have DSL - I think he may be right). Storing the temporary internet files on the hard drive significantly cuts down the amount of time it takes to completely load and view a website.

There are a few question areas, however, that need to be considered in any discussion about temporary internet files. First, and arguably the most trivial of the concerns, is that you may miss out on all of the updated information the website has to offer. If your browser loads the files from your temporary internet files folder rather than the updated material from the website, you may miss out on an updated football score, or you may get a different image than the one others are viewing. The system is designed so that things like that don't happen, but the possibility is out there.

Second, storing huge numbers of files can bog down your computer, slowing down its ability to do even the simplest of tasks, such as word processing (a deadly one-two combination if you're working with dial-up!). Fortunately, you can control the number or size of the files that are being stored on your hard drive. Typically under the Tools>Options menu of your browser you'll be able to set the amount of your hard drive you're willing to dedicate to temporary internet files. You may want to set this high or low, depending on your browsing habits and need for speed.

Third, the temporary internet files folder may contain files that contain viruses, inappropriate images or text, and files that could leak personal information to websites. This is obviously a huge concern any time you allow someone virtually unregulated access to your hard drive. Images from an inappropriate website you accidentally stumbled across (it has happened to all of us) may be stored on your hard drive. Corrupted files may be placed there by an unfamiliar website you only visited once. Cookies and other files may potentially spawn popups that cover your screen in a matter of seconds.

Before you grab your pitch fork and storm the beast's castle, let me mention a few things you can do to bring a little control to your temporary internet files folder without destroying it completely.

I already mentioned limiting the amount of your hard drive dedicated to holding files from visited websites. This is the best option for those who may be less concerned about corrupted or inappropriate files being stored and more concerned about the ability of their Jurassic-era computer to perform at a decent speed. Some versions of the popular browsers won't allow you to completely eliminate storing files, but you can limit the resources to 1% of your hard drive or a small number of megabytes.

Some opt to regularly clean out their temporary internet files folder - obviously this will eliminate malignant files and free up some space for your computer; but it will also eliminate files you may want. A quick note about the files that begin with "Cookie:" - cleaning out the folder will not actually delete the cookies. The cookie files in the temporary internet files folder are simple files that point the browser to the actual cookie in the "Cookies" folder on your hard drive. If you are interested in truly purging your system of internet files, you'll need to clean out that folder as well.

In my view, the most judicious option is to utilize available software to manage the content of your temporary internet files. Some files you want because they make your life easier. Some files you don't want because it bogs down your computer and makes your grandmother blush. Software is available that scans your computer and finds all the internet files (including cookies). The software makes recommendations as to whether the file in question is good, bad, or ugly - all you have to do is decide to keep or trash it, then click the appropriate button.

Temporary internet files can make our internet browsing time a quick and convenient experience. Unfortunately, they may also pose a risk to the security of our hard drives. With a little hands-on management we can keep ourselves, our loved ones, and our computers happy, safe, and protected.

Sunday, April 27, 2008

Internet Security Basics 101

The explosive growth of the Internet has meant that thousands of people are today experiencing the joys of being online for the first time. With growth there always comes pain. Be it your growing pains as a child or the growth and development of this part of our culture called the Internet.

Firstly we need to quickly explain what the Internet is and where it came from. The Internet is the offspring of a military project called Arpanet. Arpanet was designed to provide reliable communication during global nuclear war. A vast network of interconnected computers was set up all over the world to allow the various branches of US and NATO forces to communicate with each other.

Nuclear war never came (thankfully) and the world was left with a massive network of computers all connected together with nothing to do. Colleges and universities started to use these computers for sharing research internationally. From there it grew and spread outside colleges to local homes and businesses. The World Wide Web was born and its father was a guy called Tim Berners Lee.

When you're connected to the Internet you're sharing a vast network with hundreds of millions of other users. This shared network provides resources that 15 years ago were never thought possible. Unfortunately when something is shared its open to abuse. On the Internet this abuse comes from hackers and virus creators. Their sole intent is to cause chaos and/or harm to your computer system and millions of other computer systems all over the world.

How do you combat this? You need an Internet security system. This might sound complicated but your Internet security system will be quite straigtforward being comprised of just 2 - 3 Internet security products. We'll look at each of these products in more detail now:

AntiVirus Software

The first and most critical element of your Internet security system is antivirus software. If you don't have up-to-date antivirus software on your PC you're asking for trouble. 300 new viruses appear each month and if you're not constantly protecting your system against this threat your computer will become infected with at least one virus - it's only a matter of time.

Antivirus software scans your PC for signatures of a virus. A virus signature is the unique part of that virus. It can be a a file name, how the virus behaves or the size of the virus file itself. Good antivirus software will find viruses that haven't yet infected your PC and eliminate the ones that have.

Antivirus software can only protect your computer from viruses trying to infect it via email, CD-Rom, floppy disk, Word documents or other types of computer files. Antivirus software alone will not keep your computer 100% safe. You also need to use firewall software.

Firewall Software

The use of firewall software by home computer users is a relatively new occurence. All Internet connections are a two way process. Data must be sent and received by your computer. This data is sent through something called ports. These are not physical things rather aspects of the way your computer communicates online.

Firewall software watches these ports to make sure that only safe communication is happening between your computer and other computers online. If it sees something dangerous happening it blocks that port on your computer to make sure your computer stays safe from the person who is trying to hack into your system.

An easier way to understand a firewall would be to picture your computer as an apartment complex. At the front door of this complex there is a security guard. Every person who enters the complex must pass this security guard. If the security guard recognizes the person entering as a resident he allows them to pass without saying anything. If, however, the person entering the complex is unknown to him then he will stop that person and ask for identification. If they have no business being at the apartment complex he escorts them from the building.

If you are not currently using firewall software your computer will get hacked into - that's a guarantee.

PopUp Blocker

You can get a good popup blocker at no cost. An easy way to do this is to install either the Google or Yahoo toolbar. Both of these come with popup blockers built in. Popups are not necessarily dangerous but are a nuisance and using either of these toolbars will make your life that bit easier.

A simple rule for practicing online security is: "If in doubt then don't". If you don't recognize the file, the email address, the website or if your gut feeling says "no" then don't click that button.

Saturday, April 19, 2008

Is Your Internet Surfing Really Private?

Imagine you are surfing from your personal desktop or laptop, no one looking over your shoulder or sitting nearby. You are all alone. Wrong! From your computer identity to your personal details, you are no longer anonymous on the internet. Here's the company that you keep on the internet preventing you from surfing anonymously.

Hackers take advantage of your computer vulnerabilities to install small programs on your computer which record and relay your keyboard input. Then your information and passwords are used to hack into your bank accounts, credit cards and other financial institutions and cause you immense loss. In a similar manner, your lack of anonymous surfing leads to your professional data being stolen by hackers.

Advertisers find easy access to your computer and follow your internet activity to annoy you with popups or banner ads or both, even when you are not online. You also get bombarded with junk emails advertising products making your mailbox a spammers' heaven. Without anonymous surfing, you will find advertisers accompanying you on the web at all time.

Hijackers use tracker cookies planted into your computer to stop you from anonymously surfing. These cookies follow your surfing patterns and then hijack your searches, with or without your knowledge. Hijackers don't take your consent to install cookies and you end up on websites of hijackers' choice. Do anonymous surfing to prevent hijackings.

Con Artists send you mails disguised as those from your bank and other financial companies. Some conmen even send mails announcing you as winners and asking for your financial details. Once you give financial details you find yourself conned out of your savings. You need to practice anonymous surfing to avoid such traps.

Mischief makers abound on the internet looking for browsers without anonymous surfing habits. They use unauthorized downloads to infect your computer with viruses, worms, trojans, spyware and other harmful programs. This can lead to loss of control over your own computer. You need to keep your computer safe from mischief makers and do only anonymous surfing.

Family and Work colleagues can easily trace your internet activity from the tracks you leave on your computer. The only way to prevent this is to do anonymous surfing.

With so many disrupters and scammers, not to mention people you know, following your internet browsing you can't have any internet privacy. Safeguard your web privacy by using anonymous surfing software. Anonymous surfing software will ensure that not only is your browsing private, your data and information is also safe and secure.

If you are not using anonymous Internet surfing software, your online activities are easily tracked. Anonymizer Anonymous Surfing is anonymous web surfing software that keeps your web surfing private and secure.

Anonymizer Anonymous Surfing combines thousands of private anonymous proxy servers with 128-bit SSL technology, to ensure the highest level of protection and anonymity. Anonymous Surfing hides your online identity, hides IP address, the web sites you visit, and any information you transmit.

Friday, April 18, 2008

7 Tips for Improving Your Internet Security

Here are 7 tips you should take to heart for the security of your computer and the data it contains.

1. Always make backups of your documents and other important information stored on your computer. There is always the chance that malware can damage your operating system beyond repair. Take heed. It's better to be safe than sorry.

2. Keep your Windows operating system updated with the latest security patches from Microsoft. Windows is the most popular operating system on the planet, and consequently it is the favorite target of hackers. Also locate and install patches for your Office programs.

3. Install a software or hardware computer firewall. There are no excuses for neglecting this one. If you are using Windows XP it's built in. Go to the Security Center and make sure it's enabled. If you do not have a firewall, viruses, worms, trojans, malware and adware can all easily enter your computer via the Internet.

4. Install an antivirus program and use it! Your computer is under a constant threat while online. Make sure you have the automatic update feature enabled, and schedule it to update virus definitions on a daily basis. You can also schedule scans with most antivirus software. I have mine set to scan every night.

5. Turn off your computer and disconnect it from the internet if you are not using it. Hackers can't attack your computer if it's off line.

6. Refrain from opening e-mail attachments. Don't do it even if you recognize the sender. I use the delete button judiciously.

7. Don't run programs from unknown origins. Be especially careful with P2P sites, shareware software, and freeware applications.

Follow these tips and your computer will run longer and have fewer problems.

Sunday, February 17, 2008

Internet Security Suites

Installing the best Internet security software on one’s PC is an unwritten rule that many of us follow. We’ve heard countless horror stories of computer viruses and stolen identity; some making us swear we’ll never use the Internet again. But, let’s face it, the Web is essential to all of our lives and despite the risks, the benefits sure outweigh those detrimental aspects.

In order to fully protect your PC and find an Internet security software program you can stand hosting on your OS, it’s important to consider the following:

• Features-While most Internet security providers claim to ‘have it all,’ make sure you choose a software program with anti-virus and spyware protection, rootkit and spam protection, a firewall, and parental control functions, such as Security Shield 2008.

• Pricing-Everyone wants to save money and when choosing an Internet security software program, it’s vital to choose a great product with an affordable price tag. Security Shield 2008, for example, will run you $39.99 after mailing in their rebate.

• Ease of Use-Opt for a software program that is easy to install and doesn’t drain your system resources. CA Internet Security Suite Plus 2008, for example, provides an In-Product Tutorial if you run into any problems along your virus-scanning way.

• Customer Support-Make sure the Internet Security provider you go with has comprehensive customer support. Security Shield 2008 is covered by free technical support via email, phone and live chat. Many companies charge per-incident or by allotted time, so it’s wise to compare costs.

Most Internet security software programs run automatic updates and have real-time scanning capabilities, which are a must. Technology and Web-based threats aren’t static and in order to completely protect your PC, it’s crucial to choose a product that is both versatile and continuously updates itself.

Kelly Liyakasa is staff writer for 6StarReviews.com. Kelly Staller is site manager at 6StarReviews.com, a site dedicated to giving YOU, the consumer, the best product and service reviews around. If you like saving time and money by having someone else review leading sites and products, then Visit our site at 6StarReviews.com

Article Source: http://EzineArticles.com/?expert=Kelly_Liyakasa

Monday, February 11, 2008

“Phishing” for Suckers: Two Things You Should Look For In An email

“For Your Immediate Attention! Don’t Lose Your Account! Update Immediately!”

Bob opened the email and was confronted by the logo of one of his major credit card companies. He had been carrying the card for some time, and had used it for a lot of online purchases.

Understandably he was concerned with the message under the logo: “Due to online identity theft, we need to verify that the information in your account is accurate, or we will be required by the FTC to suspend it”.

Below was an itemized list of the information he was required to verify: his old account number, name, address, telephone number, social security number, and mother’s maiden name. The also wanted him to change the password to his account.

Panicked, Bob hit the reply button and started filling in the information. He didn’t want to lose that account. He had set up several online accounts using that credit card number, and used it to buy and sell in online auctions…

THE “PHISHERMEN” AND THEIR HOOKS

“Phishing” is a technique used by identity thieves to stampede people into giving out their credit information online. The scam has been around for awhile, and, unlike Bob, most people are aware that they should never:

• Be intimidated by a message found in an “authentic looking” email

• Reply by giving vital information to the “phishers”

• Open up any links contained within the email, which can download “criminalware” onto their computer.

We all know these facts intellectually, but when confronted by an intimidating message, many of us react emotionally, not rationally. Maybe I’m more easily intimidated than most, but I’ve found myself opening an email and feeling compelled to fill out the information the message demands.

I have to confess an incident that occurred when I almost did that very thing. In my own defense, however, I have to say that it happened before I’d ever heard the term “phishing”. Fortunately I became suspicious before hitting the “Send” button.

But I almost did it. I almost sent it off and thereby hanged myself.

THE LAKE IS GETTING CROWDED

Although the public is becoming savvier to this scam, the “phishermen” must be experiencing success because the Anti-Phishing Working Group, http://www.antiphishing.org/ reports that phishing incidents are on the upswing.

They list 28,571 consumer reported incidents in June 2006, almost double the reported numbers in June 2005.

More suckers are being “phished” than ever before, and as every honest fisherman knows, there is no bag limit on suckers.

HOW TO IDENTIFY LEGITIMATE EMAILS

Of course, the best thing to do when asked for vital information by someone purporting to be a legitimate credit card company or other institution is to call the company on the telephone and ask if the email in question does indeed come from them. Then, if it has, go to that site to change your information.

But there are a couple of “quickie” things you can look for in the email itself, which you should do if you are alarmed by the message and tempted to jump.

1. Check the “From” Address to see if the address is correct. It should come from a top level domain, i.e. ebay.com, not a sub domain such as ebay.security.com. A sub level domain can be obtained on line for free, and is not something a legitimate company would do.

2. Make Sure the “digital signature” is valid.

KNOW YOUR DIGITAL SIGNATURE

I don’t know if you’re like me, but my eyes glaze over when somebody mentions the words “digital signature”.

Basically, it’s just an electronic means of verifying that the email you received:

• Has originated from the source it claims to come from

• Hasn’t been intercepted and repackaged on the way.

An email that is “digitally signed” has a little red icon down in the lower left hand corner in the ‘To…From” box.

Click on that icon and you can find information about the sender. Be sure your email client is “S/MIME” compliant. “S/MIME” compliancy is supported by over 350 million email clients, including Microsoft Outlook, Lotus, Novel, Netscape and MacMail.

As noted on the antiphishing site, this is unspoofable for two reasons:

• It is strongly encrypted.

• It is generated when you open the email, not at the source

The email client has validated four things on receiving this email:

1. The email address in the “From” field matches the one in the digital certificate.

2. The certificate was issued by a trusted authority.

3. The message wasn’t tampered with in transit.

4. The certificate itself has not expired.

To put it simply, the certificate makes sure the email has indeed come from who it says it has come from, and hasn’t been tampered along the way.

To see what the certificate looks like, check out:

http://www.antiphishing.org/smim-dig-sig.htm

THREE WAYS TO PROTECT YOURSELF.

There are three good ways you can protect yourself from “phishermen.”

1. Call the company they supposedly represent. Don’t respond to alarming statements demanding personal information online.

2. Don’t open any links in the email. They can download “criminal ware” that can start gathering vital information off your computer.

3. Don’t open suspicious emails unless you have an “S/MIME” compliant email client and can view and open that digital icon.

LOOKING FOR SUCKERS

The phishermen are out there and still looking for suckers. Based on the rise in reported incidents they are still finding them. Armed with a little knowledge and a healthy awareness, you won’t end up in their “game bag”.

You definitely don’t want that…because the next stop is the frying pan.

Copyright 2006 John Young

John Young is a writer with a scientific and programming background. At the age of 62, he lives in California with his wife and pet cat “Bear”. His new book “Protect Yourself Against Identity Theft” can be found at: http://www.youridentitystolen.com

Sunday, February 10, 2008

Phishing : How To Recognize A Phishing Email Message

Phishing is the practice of sending fraudulent email messages supposedly from a legitimate company or organization in order to trick someone into giving out personal and confidential information. This information could include a user ID, password, credit card number or even a Social Security number. At its most basic level, Phishing is a form of identity theft. It is one of the fastest growing cyber crimes, and there are estimates that 1 in 20 people who receive a Phishing email will respond to it with their personal information. Since the criminals who send out these Phishing messages are good at what they do, it’s important to be able to recognize a Phishing email so you won’t respond to their request and become a victim of identity theft. Here are a few signs that the message you have received might just be a Phishing expedition.

• The email message is generic. Phishing emails are sent out in bulk to thousands of people, so you’ll see a generic greeting like ‘Dear Valued Customer’ and not directly addressed to you by name.

• The message gives a false sense of urgency. Phishing emails are developed and designed specifically to push the recipient to immediate action. If there is no compelling reason to respond to the message, you won’t. But if there is a fear of some kind of consequence for not providing the requested information you might just be motivated to act quickly.

This fear, urgency or even panic created by a Phishing email begins right with the subject line. Here are a few examples from actual Phishing messages:

‘Online Alert: Online Account is Blocked’

’Fraud Report’

’Credit Card Declined Notice’

’Unauthorized Account Access’

The text of the message builds upon the initial sense of urgency. A message may state that your account will be closed within 24 hours if you don t verify your information. Sometimes the messages state that there has been suspicious activity on your bank account, or your credit card has been charged by an undesirable web site.

The criminals who send out Phishing emails have taken their scam to a new level. Now people are getting Phishing messages that offer a reward for responding to the message. The newest Phishing scam is a message that states you ve won a gift card somewhere (JC Penney, Circuit City and The Sports Authority have been recent ones), and you need to click the link in the email to provide the information where the gift can be sent. Other Phishing emails offer free enrollment in a fraud protection program by clicking the link and providing the requested information.

• The message states specifically “this is not a scam”. How does that saying go if it looks like a duck and quacks like a duck, it probably is a duck. Legitimate messages don’t need to state the obvious.

• A request is made to verify your information, and a link provided for you to do so. Phishing emails will use some tactic in order to trick the recipient into providing confidential information. This request is often tied in with the false sense of urgency created in the message. The link will take you to a very authentic looking site and ask you to fill in certain personal information. If you recognize you’ve made a mistake and you try to go back to a Phishing web site you probably won’t find it. The average lifespan of a Phishing web site in December 2004 was 6 days.

The link that is included in the email message for you to click and provide information might look legitimate, but it isn’t. Often the criminals will create a web site that has almost the same name as the original web site. They might add the word “verify” or use some other word along with the company name. You should never click a hyperlink in an email, especially if you don’t know who sent it to you.

Knowledge can be power when it comes to protecting yourself from identity theft and Phishing scams. Be aware of the tricks a criminal might do to steal your information, and don’t fall prey to them.

About The Author
Colleen Durkin writes about spyware protection. Learn more at http://spyware-removal.thrcomputer.com.

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates